Live / Incidents / Liquid Web
Liquid Web: Security Advisory: Critical WordPress Vulnerability - "Click2Shell"
Liquid Web · liquidweb.comImpact: nonemonitoring2026-09-25 19:36 UTC
Public — what happened
Summary
Liquid Web Systems Engineers continue to monitor this situation closely. All Customers are strongly encouraged to confirm that all Wordpress websites they host, including those in staging or development, have been updated to the latest minor version of Wordpress released on September 22nd in order to protect the website from this exploit. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version.
For additional information, please refer to the official WordPress security announcements:
https://wordpress.org/news/2026/09/wordpress-7-1-2-release/
https://wordpress.org/document
Timeline
- Started — 2026-09-22 20:13 UTC
- Last update — 2026-09-25 19:36 UTC
- Ongoing at last check.
With SquidGrid — where it starts on the route
Independent path health
The status page is the symptom. SquidGrid measures the paths that reach Liquid Web against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.
🔒 Sign in to seeCustomers get the live Provider Assessment Report for Liquid Web: its full incident track record, what tends to break, and recent public reports of problems.
Included with any paid plan.
Open the Liquid Web report →