On July 17, the "wp2shell" security vulnerability became known in the popular CMS WordPress. This vulnerability potentially allows attackers to inject malicious code into affected web spaces. At present, we are not aware of any instances where this vulnerability has been exploited. WordPress versions 6.8 and newer are affected. The WordPress team has released new packages—versions 6.8.6, 6.9.5, 7.0.2, and 7.1 beta 2—in which the security vulnerability has been fixed.
Customers using Managed WordPress from IONOS do not need to take any action. We are applying the necessary patches automatically. We strongly recommend that all users running a self-hosted WordPress on their web space update their installation to a current version.