Important: Wordpress security vulnerability

Incident Report for ionos.co.uk

Monitoring

On July 17, the "wp2shell" security vulnerability became known in the popular CMS WordPress. This vulnerability potentially allows attackers to inject malicious code into affected web spaces. At present, we are not aware of any instances where this vulnerability has been exploited.
WordPress versions 6.8 and newer are affected. The WordPress team has released new packages—versions 6.8.6, 6.9.5, 7.0.2, and 7.1 beta 2—in which the security vulnerability has been fixed.

Customers using Managed WordPress from IONOS do not need to take any action. We are applying the necessary patches automatically.
We strongly recommend that all users running a self-hosted WordPress on their web space update their installation to a current version.

Further information regarding the security vulnerability can be found at https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
Posted Jul 20, 2026 - 18:29 BST
This incident affects: Hosting (Wordpress Hosting, Wordpress Pro).