Liquid Web Status · History · Incident #5652
ACTIVE INCIDENTWP2Shell Wordpress Core Critical Remote Code Execution Vulnerabilities, CVE-2026-60137 and CVE-2026-63030
Critical · Started Jul 17, 2026 · 9:48 PM
$HTTP_PROTOCOL = (isset($_SERVER['HTTPS']) && ($_SERVER['HTTPS'] == 'on' || $_SERVER['HTTPS'] == 1)) || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO'] == 'https') ? 'https://' : 'http://'; $SITE_URL = $HTTP_PROTOCOL . $_SERVER['SERVER_NAME'] . '/'; ?>
Liquid Web Status · History · Incident #5652
ACTIVE INCIDENTCritical · Started Jul 17, 2026 · 9:48 PM
Duration
Ongoing
Severity
Critical
Detection lead
—
User reports
—
Summary
Given the severity of this vulnerability, Liquid Web Systems Engineers have been proactively upgrading affected Wordpress applications across our fleet. Customers are still strongly encouraged to review their Wordpress websites and, if affected, to update to the patched version as soon as possible.
Started
Jul 17, 2026 · 9:48 PM
Status
Identified
Duration
Ongoing
Severity
Critical
Event timeline
Investigating
Jul 17 · 9:48 PM Liquid WebOn July 17th Wordpress.org announced two critical remote code execution (RCE) vulnerabilities commonly known as WP2Shell. These vulnerabilities exist in Wordpress Core and allow an unauthenticated request to execute arbitrary code on the target website. Customers running the Wordpress versions below are strongly advised to upgrade to latest version shown as soon as possible: Wordpress 6.8.x; fixed in 6.8.6 WordPress 6.9.x; fixed in 6.9.5 WordPress 7.0.x; fixed in 7.0.2 WordPress 7.1 beta, fixed in 7.1 beta2 Source: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ Posted 2 minutes ago. Jul 17, 2026 - 21:44 EDT
Identified
Jul 18 · 7:15 PM Liquid WebOur teams continue to work diligently to assess the impact of the recently disclosed WordPress Core vulnerabilities and verify that appropriate mitigation measures are in place. We remain actively engaged in our investigation and are monitoring the situation for any new developments. We will continue to closely monitor the situation and take any additional steps necessary to maintain system security and stability. If you need assistance or have any concerns, please contact our Support team.
Monitoring
Jul 20 · 7:43 AM Liquid WebServices have been restored, and websites are currently loading as expected. Our Network team is continuing to investigate the underlying cause and is actively monitoring the environment to ensure stability. At this time, all services appear to be operating normally. If you experience any issues or need assistance, please contact our Support team.
Identified
Jul 20 · 7:47 AM Liquid WebThe issue has been identified and a fix is being implemented.
Identified
Jul 20 · 7:48 AM Liquid WebWe are continuing to work on a fix for this issue.
Identified
Jul 20 · 4:20 PM Liquid WebGiven the severity of this vulnerability, Liquid Web Systems Engineers have been proactively upgrading affected Wordpress applications across our fleet. Customers are still strongly encouraged to review their Wordpress websites and, if affected, to update to the patched version as soon as possible.
Pulsetic catches degradations minutes before vendors acknowledge them.
Stay online, all the time, with Pulsetic's uptime prime.
By Designmodo
Designmodo Inc. 169 Madison Ave, #79627, New York, NY 10016, United States
Copyright © 2010-2026