Nexcess System Engineers have scanned our fleet and automatically upgraded WordPress websites for customers hosted on our Managed Wordpress and Managed Applications platforms.
Customers hosting Wordpress websites on our Cloudsites platform or hosting websites on managed dedicated or managed VPS servers are strongly encouraged to confirm that all Wordpress websites, including those in staging or development, have been updated to the latest minor version of Wordpress released on September 22nd in order to protect the website from this exploit.
If you have any questions or need assistance with the update process, please contact our Support team. You can reach us through the following channels:
We appreciate your patience and understanding as we work to secure your services.
Posted Sep 25, 2026 - 15:28 EDT
Update
Our Engineering team continues to assess and work on the WordPress security vulnerabilities across our hosting fleet.
A new critical vulnerability, CVE-2026-87902, has been disclosed. WordPress 7.1.2 includes the security fix for this vulnerability.
Recommended Action for Customers We strongly advise all customers managing WordPress installations to update to WordPress version 7.1.2 immediately.
We will continue to monitor the situation closely and provide further updates as new information becomes available.
Posted Sep 23, 2026 - 02:34 EDT
Identified
WordPress has identified a critical security vulnerability designated as "Click2Shell" affecting all WordPress versions prior to 7.1.1. This vulnerability can enable unauthenticated Remote Code Execution (RCE) when a logged-in administrator visits a specially crafted link. Current Status & Hosting Actions
Our engineering team is currently assessing our entire hosting fleet and determining next steps.
There are currently no known workarounds for this vulnerability other than upgrading to the latest version of WordPress.
Recommended Action for Customers
We strongly advise all customers managing WordPress installations to review their environments immediately and update to WordPress version 7.1.1.
We will continue to monitor the situation closely and provide further updates as new information becomes available.