You are here: Home News & Alerts Alerts and Malfunctions 18 July 2026, 20:03: Critical …

18 July 2026, 20:03: Critical WordPress vulnerability allows code injection via the API (wp2shell)

#ufrstatus Urgent action required: Check and update websites based on WordPress instances. Key pages of the website relaunch are not affected #wartung

On 18 July 2026, two security vulnerabilities in WordPress were disclosed. We advise all administrators to check their installations and update them to version 7.0.2 or 6.9.5.

If this is not possible, the vulnerable areas must be blocked by other means (WAF, plug-in).

You can find more information here:
https://www.heise.de/news/wp2shell-Kritische-WordPress-Luecke-erlaubt-Codeeinschleusung-ueber-API-11369660.html

You can use this tool to test your own websites for vulnerabilities:

https://wp2shell.com/

All the main web pages affected by the website relaunch have already been checked and patched.

Should we become aware of any critical WordPress versions on the web server that is managed on a decentralised basis, we reserve the right to take the sites offline temporarily.

If you have any questions, please contact webserveradmin@rz.uni-freiburg.de