Fluent Forms CVE-2026-16655: Update to 6.2.8 Now
If your site runs Fluent Forms and the plugin is below version 6.2.8, an attacker can exploit a confirmed vulnerability to manipulate or extract data from
Your WordPress site may already be compromised. If it runs any version from the 6.8.x, 6.9.x, or 7.0.x branches and has not been updated in the past few
Your WordPress site may already be compromised. If it runs any version from the 6.8.x, 6.9.x, or 7.0.x branches and has not been updated in the past few weeks, an attacker can take full administrative control of it right now — no username, no password, no interaction from you required. That is the practical reality of the wp2shell vulnerability chain disclosed in July 2026.
The attack begins with a SQL injection flaw. WordPress versions 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 contain improper sanitisation of the author__not_in parameter in WP_Query. When a plugin or theme passes untrusted input to that parameter, an attacker can manipulate the database query behind it. On its own, that is serious, but combined with a second flaw in the chain, it enables remote code execution without authentication, meaning an attacker can run arbitrary code on your server from anywhere in the world.
Public exploits for both flaws now exist, and the technical details needed to reproduce the attack are already circulating. The wp2shell vulnerability chain has been fixed in WordPress 6.9.5 and 7.0.2, but this is a known attack chain with working exploit code in the wild, not a theoretical risk waiting to materialise.
WordPress 7.0.2 addresses one critical and one high severity security issue tied to wp2shell. Critical, in security classification terms, means an attacker can achieve full system compromise without any user interaction — the ceiling of severity ratings.
The consequences of running an unpatched site are specific. An attacker can steal your customer data, deface your site, install malware that attacks your visitors, add your server to a botnet, or use your hosting account as a launchpad to attack other sites. Google detects the malware and destroys your search ranking. Your hosting provider suspends your account. If you handle any personal data, including names, email addresses, or payment information, a breach triggers UK GDPR obligations immediately.
Start at wp2shell.com, which was created specifically to let administrators check whether their site is vulnerable whilst the researchers withhold full technical details to give site owners time to patch. Use it before you do anything else, then confirm your WordPress version by logging into your admin dashboard and checking the bottom of any page, or going to Dashboard, then Updates. The safe versions are 6.8.6, 6.9.5, and 7.0.2. If you are running anything below those numbers in the respective branches, the update needs to happen today.
If your site is managed by a hosting provider, contact them directly and ask for written confirmation that the update has been applied. Many managed hosting environments apply security updates on a delay, and some require manual approval, so do not assume auto-updates ran. Ask the specific question: has WordPress been updated to 6.8.6, 6.9.5, or 7.0.2? If you have a developer maintaining your site, the same applies. Ask for confirmation, not reassurance.
The SQL injection entry point requires a plugin or theme to pass untrusted input to the author__not_in parameter, which means the risk profile of your site depends partly on which plugins and themes are active. A site running a lean, well-maintained plugin stack has a smaller attack surface than one running twenty plugins from mixed sources. If you are uncertain which of your plugins might be involved, that audit is worth doing alongside the core update.
July 2026 has been an unusual month for software security across the board. Microsoft’s July 2026 Patch Tuesday fixed 570 CVEs, the largest single Patch Tuesday release ever recorded, with 56 rated critical — the previous record was 198 CVEs. That volume reflects how much activity is happening across the industry right now. Security maintenance is a continuous operational responsibility with direct business consequences when it lapses, not a task you schedule once a quarter.
Consider the liability that sits downstream of an unpatched site. Your customers do not distinguish between “the software vendor had a flaw” and “you left a known vulnerability unpatched for three weeks after a public exploit was released”. If customer data is exposed through a breach that a patch would have prevented, regulators and customers will ask whether you acted on it when you knew, and the wp2shell disclosure, the exploits, and the patch versions have all been public since July 2026. Any breach on an unpatched site from this point is a known risk that was not addressed.
If your site is running a version below 6.8.6, 6.9.5, or 7.0.2, I can confirm your patch status, audit your plugin stack for exposure to the author__not_in attack surface, and apply the update with a verified backup taken first. Public exploits for wp2shell are already circulating, and every day an unpatched site stays live is a day it sits in the crosshairs of automated scanning tools looking for exactly this flaw. Get in touch via The WordPress Guy contact page to arrange an urgent site review.
Related articles
If your site runs Fluent Forms and the plugin is below version 6.2.8, an attacker can exploit a confirmed vulnerability to manipulate or extract data from
Two critical vulnerabilities in WordPress Core, collectively known as WP2Shell, are being actively exploited right now. If your site is running WordPress
A major WordPress update lands on 19 August 2026, timed with WordCamp US 2026, and the beta cycle is already revealing exactly why this one deserves your
Security issues need permanent fixes, not surface-level patches. This is exactly the work I specialise in.
View security services →
Jason Boyd
Specialist WordPress Engineer · Former W3C Invited Expert · 20+ years
I fix the WordPress problems other developers walk away from. Backed by a 1st Class degree in Computer Science, an MSc in Cybersecurity, and over 20 years of specialist WordPress work, I diagnose issues at their root cause and resolve them permanently — for businesses that cannot afford guesswork or repeat failures.
If this article describes your situation, I can diagnose the specifics and fix it properly. Send your brief and I'll respond the same working day.