WordPress powers a huge share of UK small business websites — shopfronts, booking pages, blogs, whole e-commerce operations. On 17 July 2026, WordPress shipped emergency updates (versions 6.9.5 and 7.0.2) to close a critical flaw researchers have named “wp2shell”: a pre-authentication remote code execution bug that works against a stock WordPress install, with no plugins and no special configuration required. In plain terms, an attacker doesn’t need a username, a password, or a phishing email to get in — the vulnerable code is reachable by anyone who can send a request to your site.
The flaw chains two issues in WordPress core’s REST API batch route, and it’s already public knowledge, complete with a working checker tool circulating online. That combination — a well-documented bug, a public proof-of-concept, and millions of unpatched sites — is exactly the recipe that turns into mass automated attacks within days of disclosure. If your site runs WordPress versions 6.9.0–6.9.4 or 7.0.0–7.0.1, it is affected until you update.
Check your version today, not this week
This isn’t a “patch when you get round to it” bug. Log into your WordPress admin dashboard, check the version number against the affected range above, and update immediately if you’re exposed. If you use a managed WordPress host, many will have already pushed the fix automatically — but don’t assume that, confirm it. If you manage your own hosting or use an agency, get confirmation in writing that the update has been applied, including the exact version number now running.
It’s also worth remembering that the flaw doesn’t need pretty permalinks turned on to be reachable, and it works through two separate access routes into the same underlying weakness. That’s a detail for whoever manages your firewall or hosting, not for you to fix by hand — but it’s exactly why “we updated one thing” isn’t the same guarantee it might be for a simpler bug. If an agency or freelancer manages your site, ask them directly whether both access routes have been checked, not just the update applied.
If you’re not sure who last touched your website, or whether anyone is actively monitoring it for security updates, that’s worth fixing regardless of this specific bug — it’s the underlying reason vulnerabilities like this sit unpatched long enough to be exploited. A huge number of small business sites are effectively unowned once the agency that built them moves on to other work, and nobody is watching for exactly this kind of alert.
Don’t stop at the update
Patching closes the door, but it doesn’t tell you whether someone already walked through it in the two days between disclosure and your update. If your site has been vulnerable, it’s worth a quick look for unfamiliar admin accounts, unexpected plugins, or changes to core files you didn’t make. For businesses that hold customer data through the site — order histories, contact forms, stored payment details via a processor — a breach here has knock-on obligations under UK data protection law, not just a technical headache.
This is the kind of gap KeepSafe exists for: ongoing monitoring that catches an incident like this early, rather than SMEs finding out weeks later when something looks wrong, a customer complains about a suspicious email, or a bank flags unusual card activity traced back to a compromised checkout page. If your website has never had a proper security review, a critical, actively-exploited core vulnerability is as good a prompt as any to get one done.
The takeaway
A pre-authentication remote code execution flaw in the world’s most popular website platform is about as serious as web security news gets for small businesses. If you run WordPress, check your version today, update if you’re in the affected range, and don’t assume “we’ll get to it” — attackers move faster than that window allows once a bug like this is public.