What’s happening
Security researchers have disclosed a vulnerability in WordPress Core itself, nicknamed “wp2shell” and tracked as CVE-2026-63030. It affects the REST API on WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1, and when chained with a second flaw, it allows remote code execution. In plain English, an attacker can potentially plant malware, steal data, or hijack a site outright, all without logging in.
WordPress released a fix on 17 July 2026. Since then, exploit code has gone public and attacks are already underway. This one moved from disclosure to active exploitation in a matter of days, which is exactly the kind of speed that catches small business websites out.
Why small business sites are usually the ones that get hit
Large platforms and agencies with dedicated security teams tend to patch within hours. The sites that get compromised in incidents like this are almost always the ones nobody is actively looking after: a site set up a few years ago, left to update itself (or not), running a stack of plugins nobody remembers installing.
If that sounds familiar, you’re not alone. Most small business owners have far better things to do than track WordPress security advisories. The problem is that a compromised website doesn’t just sit there quietly. It can get blacklisted by Google, used to send spam, or lose you customer trust the moment someone spots something isn’t right.
The three things that usually go wrong
- Slow patching- Updates get installed whenever someone remembers, which for a lot of sites means months after a fix is available, well after attackers have had time to build working exploits.
- Plugin bloat- Every extra plugin is another piece of software that can have its own vulnerabilities. Sites built with a patchwork of page builders and add-ons have a much larger attack surface than they need to.
- No monitoring or backups– If something does go wrong, the difference between a five-minute fix and a week of firefighting usually comes down to whether proper backups and monitoring were already in place.
How we do it differently at TEA Websites
Every site we manage runs on a lean build using GeneratePress and GenerateBlocks Pro, which avoids the sprawling plugin stacks that create most of this risk. Core and plugin updates, including security releases like this one, are applied promptly rather than left to chance. We also run Patchstack, which gives our sites real-time virtual patching, blocking known exploit attempts at the firewall level the moment a vulnerability is disclosed, even before we’ve had the chance to apply the official update ourselves. Every site is backed up on a regular schedule, so if the worst happened, we could restore it quickly rather than starting from zero. And because we track security advisories as part of how we run things, we’re acting on real threats within days, not finding out about them from a client after something’s already gone wrong.
This is what’s included as standard for anyone on one of our website plans. It’s not an upsell, it’s just what looking after a website properly involves.
If that sounds like the kind of thing you’d like in place for your own site, get in touch and we’ll have a chat.
If you’re not sure which WordPress version you’re running, or would like a second pair of eyes on your site’s security, get in touch and we’ll take a look.
