Forced auto-updates have shrunk the exposure window, but they do not remove a backdoor that was planted before the patch landed. The hard part on day 3 is no longer whether stock WordPress can be reached. It is finding which sites were already taken over and still look clean after updating.
WP2Shell chains CVE-2026-63030 and CVE-2026-60137 against WordPress Core 6.9.0–6.9.4 and 7.0.0–7.0.1, with 6.8.6 covering the related 6.8.x issue. WordPress has pushed 6.9.5, 7.0.2, and forced auto-updates, and Cloudflare has added mitigations. Reporting now centers on rapid webshell deployment on compromised sites, which can survive the patch.
That shifts the response from simple patching to post-patch verification across WordPress fleets. A site can be fully updated and still be backdoored, which leaves a path back into the hosting environment even after the original flaw is closed.