Introduction
This section is meant to introduce you to the core of this long-form Article.
This post is a quick coverage of a vulnerability found in WordPress that affects IONOS based WordPress installations and several other WordPress based installations. The vulnerability is entitled wp2shell and also entitled by CVE-2026-63030 on the National Vulnerability Database.
The main thing you need to do to avoid the vulnerability is to upgrade your WordPress installation to 7.0.2 or 6.9.5, this will prevent the ability for your WordPress to be compromised further, and to clear up any potential mess check through your WordPress installation for any files you didn't put there, and that strike you as suspicious.
IONOS Instructions
The following is how IONOS describes the issue, and how you can tackle it.
The wp2shell vulnerability is described as a critical issue that can affect all WordPress installations worldwide. This means that visitors to your site could be exposed if the vulnerability is not mitigated. To protect your site users you should:
1. Change all relevant passwords as described above and avoid entering any new passwords into the WordPress site until the security situation is resolved.
2. Ensure the IONOS Security plugin is installed and that the daily security scan is active. The scan checks plugins, themes, and the WordPress core for known vulnerabilities.
3. Review the scan results in the WordPress admin panel under IONOS Tools & Security. If a vulnerability is reported, follow the recommended measures such as installing available updates or temporarily deactivating the affected plugin or theme.
4. Keep WordPress core, plugins, and themes up to date to reduce the risk of exploitation.
For more technical details you can consult the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-63030. If you need further assistance, please contact IONOS support directly (support@ionos.com).
![Dear [Chaosyr]
A security vulnerability dubbed "wp2shell" in the WordPress content management software has become known. This potentially allows attackers to inject malicious code into web spaces running the WordPress software prior to a specific version and access your data.
Potentially, all WordPress installations worldwide are affected. You can find further technical information about this vulnerability here: National Vulnerability Database
During a security scan, we found strong indications that your WordPress installation may be the victim of such an attack and that your files and/or databases have been compromised.
Please log in to your IONOS account immediately and change your passwords:
• Customer password
• E-mail passwords
• Passwords or credentials (e.g., API keys, tokens) for all programs and extensions (plugins) connected to your WordPress site (e.g., for your online shop)
If you have saved passwords in your WordPress instance that you also use for other services or accounts, please change them immediately with the respective providers for security reasons.
IMPORTANT: Under no circumstances should you enter changed passwords or access data into your WordPress. Attackers could otherwise gain access to your data.
We are working diligently on further security measures for your WordPress installation and will inform you shortly about the next steps.
Best wishes,
Signature of Jens Reich
Jens Reich
CCO IONOS](https://stoatgames.icu/wp-content/uploads/2026/07/image.png)
How this affects Stoat Games
This section covers how the situation affects us.
From what I have found we haven't been affected, and we were on 7.0.2. prior to IONOS contacting us, I've removed some files I don't recall being there on my end. But for the future, here is our security policy (temporary until we write one, this is a 1 man team at the moment).
- If you find any sort of Vulnerability contact us via Contact&Support@stoatgames.icu directly, and we will work with you on resolving the issue.
- If you know someone who has been affected by the Vulnerability have them contact us, when we give you the go ahead to do so.
- We want to take security of this site as seriously as we can, so if any incidents pop up we will be informing you via this news feed, and updating you on the situation that way.
This will be much more in depth in terms of a security policy when we have someone that can handle anything security related for the website themselves. (And these cases should be much more timely by than as well.)
Conclusion
This section is the outro to this Article, and acts as a rough summary.
To conclude, there was a vulnerability in WordPress in which this article aims to make you more aware of, and provide official ways for you to resolve the issue in terms of IONOS based products, and to let you know how you can resolve it in the future.
If any details in this article are incorrect let us know and we'll amend it with the fixes. The comment section is our friend, and should be yours as well.

