Important: Wordpress security vulnerability

Incident Report for ionos.co.uk

Update

We are continuing to monitor for any further issues.
Posted Jul 27, 2026 - 11:53 BST

Update

We are continuing to monitor for any further issues.
Posted Jul 21, 2026 - 13:33 BST

Monitoring

On July 17, the "wp2shell" security vulnerability became known in the popular CMS WordPress. This vulnerability potentially allows attackers to inject malicious code into affected web spaces.

WordPress versions 6.8 and newer are affected. The WordPress team has released new packages—versions 6.8.6, 6.9.5, 7.0.2, and 7.1 beta 2—in which the security vulnerability has been fixed.

Customers using Managed WordPress from IONOS do not need to take any action. We are applying the necessary patches automatically.
We strongly recommend that all users running a self-hosted WordPress on their web space update their installation to a current version.

Further information regarding the security vulnerability can be found at https://www.ionos.co.uk/help/index.php?id=28591
Posted Jul 20, 2026 - 18:29 BST
This incident affects: Hosting (Wordpress Hosting, Wordpress Pro).