wp2shell Vulnerability Checker
Instantly check whether your WordPress site is running a version exposed to wp2shell - the critical, actively exploited pre-authentication RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137).
On July 17, 2026, WordPress patched wp2shell - a critical flaw that lets an anonymous attacker run code on a default WordPress site with no login, no plugins, and no user interaction. Public proof-of-concept exploits are already circulating and attacks are active in the wild. Digital Warfare checks the one thing that matters right now: whether your site's WordPress core version falls in the exposed range. Enter your URL and we read your public version information - the same data any visitor sees - then tell you in seconds whether you need to patch. No exploitation. No break-in. Just a clear answer and your next step.
No login required. Version check only. Results in seconds.
Run a free wp2shell check and know in seconds whether your WordPress site needs to be patched.

Check My Site for wp2shell
What the wp2shell Check Looks For

Your WordPress core version - the check identifies the version your site publicly reports.

The exposed ranges - WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 carry the full wp2shell RCE chain.

The SQL-injection branch - CVE-2026-60137 also affects WordPress 6.8.0–6.8.5.

Patch status - whether your version is at or above the fixed releases (6.9.5, 7.0.2, or 6.8.6).

A clear verdict - Exposed or Not Exposed, plus the exact version you should be running.
How It Works

Why wp2shell Is a "Patch Today" Emergency
wp2shell is a pre-authentication remote code execution chain in WordPress core. It combines a REST API batch-route confusion flaw (CVE-2026-63030) with a SQL injection in WP_Query (CVE-2026-60137) to let an unauthenticated attacker take over a default WordPress site. What makes it urgent:
- It requires no account, no plugins, and no special configuration.
- It affects WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1.
- It was disclosed on July 17, 2026, and public proof-of-concept exploits appeared within hours.
- Both CVEs were added to CISA's Known Exploited Vulnerabilities catalog on July 21, 2026, confirming active exploitation.
- Because it lives in core - not a plugin - you can't deactivate your way out. You must update.
Your Result

A clear Exposed / Not Exposed verdict for wp2shell

The WordPress core version we detected

The exact fixed version you should be running (6.9.5 or 7.0.2)

Plain-English guidance on how to patch and confirm it worked

What to review if your site ran a vulnerable version
We Test Version Numbers. We Never Exploit.
Digital Warfare's wp2shell check is strictly defensive. We determine your WordPress core version from information your site already makes public and compare it to the affected ranges - nothing more. We never send the wp2shell exploit, never attempt to run code, and never access anything a normal visitor couldn't see. Use it on sites you own or are authorized to test. It's a smoke detector, not a break-in.
Versions Affected
The full wp2shell remote code execution chain affects the following WordPress core versions:
- WordPress versions below 6.9.0 — Not affected by the wp2shell RCE chain
- WordPress 6.9.0 through 6.9.4 — Affected (fixed in 6.9.5)
- WordPress 7.0.0 through 7.0.1 — Affected (fixed in 7.0.2)
Sites running any version outside the ranges above are not vulnerable to this specific RCE chain.
Note on the SQL injection component: One of the two flaws in the chain, CVE-2026-60137, is a SQL injection that independently affects WordPress 6.8.0 through 6.8.5 (fixed in 6.8.6). These versions are not exposed to the complete pre-authentication RCE, but should still be updated to close the underlying SQL injection.
Recommended Actions
The only reliable long-term protection is to update WordPress immediately.
- Update to WordPress 6.9.5 or later if you are on the 6.9 branch.
- Update to WordPress 7.0.2 or later if you are on the 7.0 branch.
- Update to WordPress 6.8.6 or later if you are on the 6.8 branch, to close the related SQL injection (CVE-2026-60137).
WordPress enabled forced automatic updates for these releases. Because forced updates do not always complete — for example on sites with disabled auto-updates, file-permission issues, or custom configurations — confirm that your site is actually running a fixed version after updating.
Temporary mitigations (until the update is applied)
These reduce exposure but do not fix the underlying vulnerability. Apply the official update as soon as possible.
- Block the batch REST endpoint at your WAF or web server. Deny requests to the path /wp-json/batch/v1 and to the equivalent query-string form rest_route=/batch/v1 (used when pretty permalinks are disabled).
- Restrict unauthenticated access to the WordPress REST API. Prefer targeting the batch endpoint specifically — blanket-blocking the entire REST API can break the block editor, contact forms, and other legitimate features that rely on it.
- Require authentication for REST batch requests using a small custom (must-use) plugin that rejects unauthenticated calls to the batch route.
Each of these is a stopgap. Applying the official security update (6.9.5 / 7.0.2) remains the required solution.
Verify You're Protected
After updating or applying a mitigation, confirm it worked:
- Check your version under Dashboard → Updates or in the admin footer, and confirm it is 6.9.5, 7.0.2, or later.
- Re-run the wp2shell check to confirm your site reports a fixed version.
- If you applied the WAF rule, confirm that requests to /wp-json/batch/v1 are blocked.
- Retest on this page

Think You're Already Patched? Confirm It.
WordPress enabled forced automatic updates for the fixed releases - but forced updates don't always complete. Sites with disabled auto-updates, file-permission issues, or custom configurations can be left behind on a vulnerable version. A 30-second check confirms whether the patch actually landed on your site.
Built For

Business owners
On WordPress who need to know right now if they're exposed

Agencies
Triaging dozens of client sites against a live, active threat

IT and security teams
Confirming that forced auto-updates actually completed

Anyone
unsure which WordPress version their site is running

Why Digital Warfare
When a core WordPress vulnerability goes from disclosure to in-the-wild exploitation in a matter of hours, speed and clarity are everything. Digital Warfare tracks critical WordPress threats as they break and gives you a single, unambiguous answer: are you exposed, and what do you do next? No jargon, no fear-selling - just the fastest path from "not sure" to "secured."
Client Testimonials
wp2shell FAQ
Frequently Asked Questions
wp2shell - Key Facts
- wp2shell is a critical pre-authentication RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137).
- It affects WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1; the SQL-injection component also affects 6.8.0–6.8.5.
- It is fixed in WordPress 6.9.5, 7.0.2, and 6.8.6 (released July 17, 2026).
- It requires no login, no plugins, and no user interaction.
- It is being actively exploited; both CVEs are in CISA's KEV catalog as of July 21, 2026.
- Digital Warfare's checker tests your WordPress core version only - no exploitation.








