WordPressRCECybersecurityPatchCanadaSMB

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

July 18, 2026

Back to all posts

Source: BleepingComputer

A critical vulnerability, known as 'wp2shell', has been discovered in the core of WordPress versions 5.7 and earlier. This security flaw could potentially allow attackers to execute remote code (RCE) on affected websites. The exploit was initially made private but has since become publicly available, putting numerous Canadian businesses using WordPress at risk. Given that WordPress powers approximately 40% of all websites worldwide, it's essential for Canadian SMB owners and IT managers to patch their systems immediately to avoid potential data breaches or website takeovers. The WordPress security team has released a fix for this issue; it is highly recommended to update your WordPress installations as soon as possible.
WordPressRCECybersecurityPatchCanadaSMB

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment