{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Teams, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-08-13T04:08:36.087Z"
  },
  "data": {
    "id": "incident_statuspage_pantheon_m2ypw5lvgknb",
    "slug": "pantheon-wordpress-7-0-2-wp2shell-2026-07-20",
    "title": "WordPress 7.0.2 wp2shell",
    "summary": "WordPress 7.0.2 wp2shell",
    "status": "resolved",
    "severity": "major",
    "startedAt": "2026-07-20T19:26:50.218+00:00",
    "updatedAt": "2026-07-21T21:33:38.263+00:00",
    "resolvedAt": "2026-07-21T21:33:38.248+00:00",
    "provider": {
      "slug": "pantheon",
      "name": "Pantheon"
    },
    "affectedServices": [
      {
        "slug": "pantheon-cdn",
        "name": "Global CDN"
      }
    ],
    "links": {
      "html": "/incidents/pantheon-wordpress-7-0-2-wp2shell-2026-07-20",
      "api": "/api/v1/incidents/pantheon-wordpress-7-0-2-wp2shell-2026-07-20",
      "providerHtml": "/providers/pantheon",
      "alerts": "https://outagedeck.com/account?stack=pantheon&utm_source=api&utm_medium=response&utm_campaign=api_alerts&utm_content=incident"
    },
    "impactSummary": "Pantheon reported a major event for the affected tracked services.",
    "source": {
      "id": "source_pantheon_status",
      "kind": "official_api",
      "name": "Pantheon Operations Status",
      "checkedAt": "2026-08-13T04:00:29.141+00:00",
      "officialUrl": "https://status.pantheon.io",
      "statusPageUrl": "https://status.pantheon.io"
    },
    "updates": [
      {
        "id": "update_statuspage_pantheon_m2ypw5lvgknb_6kkxp77nxklc",
        "status": "monitoring",
        "body": "Summary \nOn July 17, 2026, the WordPress security team disclosed two chained vulnerabilities in WordPress core, publicly referred to as \"wp2shell\":\n\n- CVE-2026-60137 — a SQL injection issue in WordPress core (WP_Query / author__not_in).\n- CVE-2026-63030 — a REST API batch-route confusion issue which, chained with the above, can lead to unauthenticated remote code execution.\n\nWho is affected\nThis affects specific versions of WordPress core:\n\n- 6.9.x — affected by both issues (RCE-capable). Patched in 6.9.6.\n- 7.0.x — affected by both issues (RCE-capable). Patched in 7.0.2.\n- 6.8.x — affected by the SQL injection issue only (not the full RCE chain). Patched in 6.8.6.\n\nSites already on 6.8.6 / 6.9.6 / 7.0.2 or later, or on versions prior to 6.8, are not affected by this chain.\n\nWhy it matters\nChained together, these vulnerabilities can allow an unauthenticated attacker to execute code against a vulnerable site. \n\nPantheon’s immutable containers prevent the deployment of webshells, bitcoin miners, or other exploits that leverage a downloaded payload in production environments. However, SQL Injection can still be used to deface or hijack sites.\n\nBecause working exploits are publicly available, we expect attack volume to rise.\n\nWhat you should do — action required\nUpdate WordPress core to a patched version as soon as possible — 7.0.2, 6.9.6, or 6.8.6 depending on your branch — from your Pantheon Dashboard or via Terminus. Updating core is the definitive fix. See the WordPress 7.0.2 Security Release note: https://docs.pantheon.io/release-notes/2026/07/wordpress-7-0-2\n\nWhat Pantheon is doing\n- We are actively monitoring platform traffic for exploitation attempts targeting the affected REST API endpoint.\n- We have observed sites being probed for vulnerability and have actively mitigated against sources of scripted activity already.\n- We are deploying targeted mitigations at the network level to programmatically prevent exploit attacks across the platform and can confirm that released exploit code is being mitigated.\n- Will update this post with more information as those efforts progress.",
        "createdAt": "2026-07-20T19:26:50.316+00:00"
      },
      {
        "id": "update_statuspage_pantheon_m2ypw5lvgknb_fj68x4t283t1",
        "status": "monitoring",
        "body": "We can observe our mitigations denying an increasing volume of requests and are continuing to gather data to enhance our response. \n\nWe will provide an update Tuesday morning.",
        "createdAt": "2026-07-20T22:20:06.355+00:00"
      },
      {
        "id": "update_statuspage_pantheon_m2ypw5lvgknb_gfc548fj7hf7",
        "status": "monitoring",
        "body": "We are continuing to monitor traffic patterns and adapt network-level mitigations in response.",
        "createdAt": "2026-07-21T13:43:38.166+00:00"
      },
      {
        "id": "update_statuspage_pantheon_m2ypw5lvgknb_24blmzyq8x91",
        "status": "monitoring",
        "body": "Network mitigations are now active and successfully blocking exploit attempts against vulnerable API endpoints without affecting normal site operations. Continuous monitoring is in place.\n\nThis platform-level mitigation is a safeguard, not a permanent fix for your application. To fully secure your environment, update WordPress core immediately as detailed in the Pantheon Documentation: https://docs.pantheon.io/core-updates",
        "createdAt": "2026-07-21T21:33:01.59+00:00"
      },
      {
        "id": "update_statuspage_pantheon_m2ypw5lvgknb_x942wtd2w9nd",
        "status": "resolved",
        "body": "This incident has been resolved.",
        "createdAt": "2026-07-21T21:33:38.248+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}