Rejuvenate IT Logo

WordPress patched a flaw that let strangers take over a site with no login – check your version

On 17 July WordPress released versions 7.0.2 and 6.9.5 to close a pair of flaws that security researchers nicknamed wp2shell. On their own neither is dramatic. Chained together, as The Hacker News reported, they let somebody with no account and no password run their own code on the site and take it over completely.

The first flaw sits in the part of WordPress that handles bundled requests, the second in the way it builds database queries. Security firm Tenable describes the trick behind it: a request path beginning with three slashes is read one way by the check that decides whether you are allowed in, and a different way by the code that carries the request out. The check passes. The request runs anyway.

This one matters more than the usual plugin advisory because the hole was in WordPress itself rather than an add-on, so every site was in scope regardless of what was installed. A working proof of concept was circulating within hours of the announcement, and CISA added it to its list of flaws under active attack on 21 July.

Who this affects

Sites running WordPress 6.9.0 to 6.9.4, or 7.0.0 to 7.0.1. The fixed versions are 6.9.5 and 7.0.2.

There is genuinely good news here: WordPress.org pushed this one out as a forced automatic update, so a great many sites were repaired without anybody lifting a finger. The ones left behind are the predictable ones – sites where automatic updates were switched off deliberately, sites on a host that batches updates and applies them on its own schedule, and the copies everyone forgets. An old staging site or a “temporary” duplicate from a redesign runs the same WordPress as the real thing, and attackers scan for those just as happily.

What to check

  • Confirm the version. Sign in and look at Dashboard → Updates. Anything below 6.9.5, or below 7.0.2 on the newer line, still needs doing.
  • Check automatic updates are actually on. This one was forced out, but the next will not be. A site that cannot update itself will always be late.
  • Do not forget the spares. Staging sites, old redesign copies, that microsite from a campaign three years ago. Same software, same flaw, usually nobody watching.
  • Ask your host what they did, and when. Managed hosts often patched centrally within hours. That is worth knowing rather than assuming.
  • If you were slow to update, look for company. Check for administrator accounts you do not recognise and for files changed around the time you patched. Fixing the hole does not remove anyone who came through it first.

If you would rather not go looking

Most business owners have no reason to know which version of WordPress they are on, and no particular wish to find out. Keeping sites current, watching for the flaws that matter and dealing with the forgotten staging copy is ordinary work for us rather than a project – it is what our website maintenance and hosting security cover, with round-the-clock monitoring behind them so a break-in does not wait for somebody to notice.

Call us on 01202 237 273 or book a call.