New Multi-region uptime checks and custom-domain status pages

Security Advisory: Critical WordPress Vulnerability - "Click2Shell"

None Impact Monitoring Ongoing per provider September 22, 2026
View the provider incident record →

Current answer

Liquid Web - Cloud Sites experienced a none incident: Security Advisory: Critical WordPress Vulnerability - "Click2Shell". The provider currently marks this incident Monitoring.

Looking for an update now? Check the current status, or follow Liquid Web - Cloud Sites for future changes.

Incident Lifecycle

Investigating Identified Monitoring

Incident Timeline

Monitoring
Liquid Web Cloudsites Engineers continue to monitor this situation closely. Cloudsites Customers hosting Wordpress websites are strongly encouraged to confirm that all Wordpress websites, including those in staging or development, have been updated to the latest minor version of Wordpress released on September 22nd in order to protect the website from this exploit. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version.

For additional information, please refer to the official WordPress security announcements:
https://wordpress.org/news/2026/09/wordpress-7-1-2-release/
https://wordpress.org/documentation/wordpress-version/version-7-1-2/

If you have any questions or need assistance with the update process, please contact our Support team. You can reach us through the following channels:

Live Chat via the Customer Portal: https://my.liquidweb.com/
Email: support@liquidweb.com

We appreciate your patience and understanding as we work to secure your services.
Sep 25, 2026 at 7:35 PM UTC
Identified
Our Engineering team continues to assess and work on the WordPress security vulnerabilities across our hosting fleet.

A new critical vulnerability, CVE-2026-87902, has been disclosed. WordPress 7.1.2 includes the security fix for this vulnerability.

Recommended Action for Customers

We strongly advise all customers managing WordPress installations to update to WordPress version 7.1.2 immediately.

We will continue to monitor the situation closely and provide further updates as new information becomes available.
Sep 23, 2026 at 6:36 AM UTC
Investigating
WordPress has identified a critical security vulnerability designated as "Click2Shell" affecting all WordPress versions prior to 7.1.1. This vulnerability can enable unauthenticated Remote Code Execution (RCE) when a logged-in administrator visits a specially crafted link.
Current Status & Hosting Actions

Our engineering team is currently assessing our entire hosting fleet and determining next steps.

There are currently no known workarounds for this vulnerability other than upgrading to the latest version of WordPress.

Recommended Action for Customers

We strongly advise all customers managing WordPress installations to review their environments immediately and update to WordPress version 7.1.1.

We will continue to monitor the situation closely and provide further updates as new information becomes available.
Sep 22, 2026 at 8:12 PM UTC
Was your business affected by this Liquid Web - Cloud Sites outage?
Follow Liquid Web - Cloud Sites and route available status alerts to email or a team channel.