Quick summary
On 17 July 2026 wp2shell broke — the most serious WordPress core security flaw in nearly a decade: it lets an attacker take over a website with no password and no login. According to Wiz, 1 in 4 WordPress installations had a vulnerable server exposed to the Internet the day it was disclosed, and it was weaponized in 90 minutes. This isn't bad luck: it's proof that AI has changed the game in web development. Want to know if your site is affected? Scan it free in seconds.
What happened: the worst WordPress hole in a decade
It's not an obscure plugin or a bad setup. It's a flaw in the core of WordPress —the code running on hundreds of millions of sites—. It's called wp2shell and it chains two real vulnerabilities disclosed on 17 July 2026: CVE-2026-63030 (route confusion in the REST API, rated 9.8 out of 10 · critical) and CVE-2026-60137 (SQL injection). Together they produce the worst thing possible: unauthenticated remote code execution. In plain words: a stranger, with no username or password, can break into your site and make it theirs.
The severity is historic. Wordfence describes it as the first critical unauthenticated WordPress core RCE in nearly a decade. WordPress had to do something it almost never does: force automatic updates worldwide. And the US agency CISA added it to its catalog of actively exploited vulnerabilities on 21 July. This isn't theory: it's happening right now.
1 in 4 WordPress sites was exposed
Here's the number that stings. According to Wiz research, at the time of disclosure:
25%
of WordPress sites had a vulnerable server exposed to the Internet (1 in 4)
60%
of organizations had at least one vulnerable instance
90 min
is how long attackers took to weaponize the exploit and start scanning
And mind the word "exposed": because the attack needs no password, against a vulnerable, unpatched site the success rate is practically total. Being exposed means being one click away from being taken over. The window between "the flaw is public" and "half the internet is exploiting it" was measured in minutes, not weeks.
The goal: fooling Google (without you noticing)
Why would an attacker want your site? Often not to take it down —you'd notice that— but for something quieter and more profitable: hijacking your Google rankings. It's a technique called cloaking (or "SEO spam"): the site shows Google different content than it shows you. To you everything looks normal; to the search engine, your domain starts serving spam, fake pharmacies or counterfeit stores, dragging down your reputation and traffic. Google itself defines cloaking as "presenting different content to users and search engines to manipulate rankings".
The dangerous part: you can be hacked for months without knowing. There's no "you've been hacked" banner. Just odd traffic drops, strange results in Google or Search Console warnings… by the time it's too late.
Why this changes everything: AI no longer plays for you
A core flaw being mass-exploited within hours is no accident: it's the new normal. With public exploits and automated scanning, attackers no longer hunt victims one by one: they sweep the entire internet at machine speed. AI gives them wings —it finds targets, adapts the attack and launches it at scale— in the time it takes you to read an email.
And here's the structural problem with classic CMSs. WordPress, and by the same logic Drupal, PrestaShop and the rest, are open-source monoliths with millions of identical copies. A single core flaw is a master key that opens a quarter of the internet at once. They were brilliant for their time. But in a world where the attacker attacks with AI, defending yourself with a pile of plugins and manual patches is late by definition.
The answer is also AI: hablo's agents
Let's be blunt: if the attack is powered by AI, the defense has to be powered by AI too. That's where hablo comes in. hablo isn't a CMS waiting for the next core flaw: it's a Personal AI Agent working for you. Among the things it can do for your digital presence:
- Clean your WordPress if it's already been breached: a hablo Agent helps you find and remove the malicious code, webshells and injected SEO spam, and get it clean and up to date.
- Watch your website and your Search Console and alert you at the first odd sign (a new redirect, content you didn't add, a suspicious traffic drop).
- Detect the kind of manipulation wp2shell performs: cloaking, SEO spam, changes only search engines can see.
- Guide you step by step if something smells wrong, in your language and without jargon.
It's not magic or a promise of an "unhackable site" —that doesn't exist—. It's having AI on your side, watching 24/7, instead of waiting for the next flaw to catch you not looking.
Check it yourself
Has your site been hacked?
Scan it free with the INTERDIGITAL scanner: it detects in seconds content manipulated for search engines, vulnerable versions, exposed files and remote-control tools —exactly what wp2shell leaves behind.
Only scan sites you own or are authorized to test. A remote check detects signs of exposure and compromise, but is not a substitute for a full forensic audit.
What to do if you use WordPress (now)
- Update the core to 7.0.2, 6.9.5 or 6.8.6 (or higher). Most sites will have auto-updated, but verify it.
- Scan your site with the scanner above to see if it shows signs of compromise.
- If you were unpatched between 17 and 21 July, check for signs of intrusion: admin users you don't recognize, modified files, strange redirects or spam results in Google.
- Put AI on your side so you don't depend on remembering to look: let an agent watch it for you.
FAQ
What exactly is wp2shell?
It's the industry name for the chain of two WordPress core vulnerabilities (CVE-2026-63030 + CVE-2026-60137) that, combined, let an attacker execute code and take over the site with no username or password.
How do I know if my site is affected?
If you use WordPress and you're not on 7.0.2 / 6.9.5 / 6.8.6 or higher, you're exposed. The fastest way to be sure is to scan your site with the scanner.
Is updating enough?
Updating protects you from future attacks, but it does not clean a site that was already compromised before the patch. That's why you should update and check for signs of intrusion.
How do I know if I've already been hacked without noticing?
Look for cloaking or SEO spam signs: strange results for your domain in Google, Search Console warnings, redirects or unexplained traffic drops. The scanner helps detect these signs in seconds.
How do I clean my WordPress?
If your site is already compromised, updating isn't enough: you have to remove what the attackers left behind. A hablo Agent helps you find and delete the malicious code, webshells and injected SEO spam, review suspicious users and access, and leave your WordPress clean and up to date, guiding you step by step or doing the heavy lifting for you.
Does hablo use WordPress?
No. That's exactly the point: hablo is a Personal AI Agent, not a monolithic CMS with a core shared by half the internet. Its approach is putting AI to work for you —including watching over your online presence.
Sources
NVD · CVE-2026-63030 · WordPress.org · 7.0.2 security release · Wiz Research (25% / 60% exposure data) · Wordfence · CISA KEV (21 Jul 2026).
AI isn't only the attacker's weapon. Make it your defense too.
hablo puts a Personal AI Agent to watch over you —in your language, 24/7— for €9.99/mo. Try the demo with a real person.