20/07/2026
SERVICE STATUS
We are posting this announcement to make you aware of a critical security vulnerability affecting WordPress Core, known as wp2shell.
What's the issue?
Security researchers have identified a serious flaw in WordPress itself (not a plugin or theme) that could allow an attacker to remotely run malicious code on a vulnerable site without needing to log in first.
The tech bit.
It affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, and given how widely WordPress is used, this is a high-severity issue the datacentre are taking this issue seriously. Versions 6.8.5 and below are not affected.
The problem.
The datacentre we use has already applied a protective rule at our Web Application Firewall (WAF) level across all shared hosting accounts, blocking the attack pattern used to exploit this vulnerability. This protection is already active. However some websites are not responding now that the new settings have been applied. We are working to rectify this as soon as possible.
Action to take.
If you are affected send an email to [email protected] outlining your problem and we will look into this as a matter of urgency.
What is not affected.
Most users are not affected and for those who are, their email should continue to work as normal.
We thank you for your patience and look forward to a speedy resoluton.