18 July 2026, 20:03: Critical WordPress vulnerability allows code injection via the API (wp2shell)
On 18 July 2026, two security vulnerabilities in WordPress were disclosed. We advise all administrators to check their installations and update them to version 7.0.2 or 6.9.5.
If this is not possible, the vulnerable areas must be blocked by other means (WAF, plug-in).
You can find more information here:
https://www.heise.de/news/wp2shell-Kritische-WordPress-Luecke-erlaubt-Codeeinschleusung-ueber-API-11369660.html
You can use this tool to test your own websites for vulnerabilities:
https://wp2shell.com/
All the main web pages affected by the website relaunch have already been checked and patched.
Should we become aware of any critical WordPress versions on the web server that is managed on a decentralised basis, we reserve the right to take the sites offline temporarily.
If you have any questions, please contact webserveradmin@rz.uni-freiburg.de