IONOS US experienced a minor incident on July 20, 2026 affecting Wordpress Hosting and Wordpress Pro, lasting 28d 19h. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- monitoring Jul 20, 2026, 05:21 PM UTC
On July 17, the "wp2shell" security vulnerability became known in the popular CMS WordPress. This vulnerability potentially allows attackers to inject malicious code into affected web spaces. At present, we are not aware of any instances where this vulnerability has been exploited. WordPress versions 6.8 and newer are affected. The WordPress team has released new packages—versions 6.8.6, 6.9.5, 7.0.2, and 7.1 beta 2—in which the security vulnerability has been fixed. Customers using Managed WordPress from IONOS do not need to take any action. We are applying the necessary patches automatically. We strongly recommend that all users running a self-hosted WordPress on their web space update their installation to a current version. Further information regarding the security vulnerability can be found at https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
- monitoring Jul 21, 2026, 12:32 PM UTC
We are continuing to monitor for any further issues.
- monitoring Jul 21, 2026, 12:34 PM UTC
We are continuing to monitor for any further issues.
- monitoring Jul 27, 2026, 10:51 AM UTC
We are continuing to monitor for any further issues.
- resolved Aug 18, 2026, 01:05 PM UTC
The issue has been resolved.