Investigating - WordPress has identified a critical security vulnerability designated as "Click2Shell" affecting all WordPress versions prior to 7.1.1. This vulnerability can enable unauthenticated Remote Code Execution (RCE) when a logged-in administrator visits a specially crafted link.
Current Status & Hosting Actions

Our engineering team is currently assessing our entire hosting fleet and determining next steps.

There are currently no known workarounds for this vulnerability other than upgrading to the latest version of WordPress.

Recommended Action for Customers

We strongly advise all customers managing WordPress installations to review their environments immediately and update to WordPress version 7.1.1.

We will continue to monitor the situation closely and provide further updates as new information becomes available.

Sep 22, 2026 - 15:12 CDT
PHP Services Operational
LAN Operational
PHX Operational
IIS Services Operational
LAN Operational
PHX Operational
MariaDB Operational
LAN Operational
PHX Operational
MSSQL Operational
LAN Operational
PHX Operational
FTP Operational
LAN Operational
PHX Operational
Management Portal Operational
Management Portal Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance

Sep 22, 2026

Unresolved incident: Security Advisory: Critical WordPress Vulnerability - "Click2Shell".

Sep 21, 2026

No incidents reported.

Sep 20, 2026

No incidents reported.

Sep 19, 2026

No incidents reported.

Sep 18, 2026

No incidents reported.

Sep 17, 2026

No incidents reported.

Sep 16, 2026

No incidents reported.

Sep 15, 2026

No incidents reported.

Sep 14, 2026

No incidents reported.

Sep 13, 2026

No incidents reported.

Sep 12, 2026

No incidents reported.

Sep 11, 2026

No incidents reported.

Sep 10, 2026

No incidents reported.

Sep 9, 2026

No incidents reported.

Sep 8, 2026

No incidents reported.