IONOS Status · History · Incident #5703

ACTIVE INCIDENT

Important: Wordpress security vulnerability

Minor · Started Jul 20, 2026 · 1:21 PM

  • Duration

    Ongoing

  • Severity

    Minor

  • Detection lead

  • User reports

Summary

Important: Wordpress security vulnerability

We are continuing to monitor for any further issues.


  • Started

    Jul 20, 2026 · 1:21 PM

  • Status

    Monitoring

  • Duration

    Ongoing

  • Severity

    None

Event timeline

How this incident unfolded

  • Monitoring

    Jul 20 · 1:21 PM IONOS

    On July 17, the "wp2shell" security vulnerability became known in the popular CMS WordPress. This vulnerability potentially allows attackers to inject malicious code into affected web spaces. WordPress versions 6.8 and newer are affected. The WordPress team has released new packages—versions 6.8.6, 6.9.5, 7.0.2, and 7.1 beta 2—in which the security vulnerability has been fixed. Customers using Managed WordPress from IONOS do not need to take any action. We are applying the necessary patches automatically. We strongly recommend that all users running a self-hosted WordPress on their web space update their installation to a current version. Further information regarding the security vulnerability can be found at <a href="https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/">https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/</a>

  • Monitoring

    Jul 21 · 8:32 AM IONOS

    We are continuing to monitor for any further issues.

  • Monitoring

    Jul 21 · 8:34 AM IONOS

    We are continuing to monitor for any further issues.

Get alerted before the next IONOS outage.

Pulsetic catches degradations minutes before vendors acknowledge them.

Start monitoring free