Server Status - zFast Limited

Network Status

We are aware of a potentially service impacting issue. Learn more
WordPress Security Advisory — REST API Batch Endpoint (CVE-2026-60137 / CVE-2026-63030) (In Progress) Critical

Affecting Other - Wordpress

  • 23/07/2026 13:00
  • Last Updated 26/07/2026 17:51

Two critical WordPress core vulnerabilities have recently been disclosed. The first (CVE-2026-60137) is a SQL injection flaw in WordPress's query handling; the second (CVE-2026-63030) chains with it to allow unauthenticated remote code execution via the REST API. As an example of what this vulnerability allows, an attacker can create a new wordpress admin user into a website, thereby gaining full access at an administrative  level to the website.  Both are actively exploited in the wild and are listed on the CISA Known Exploited Vulnerabilities catalogue.  The combination of these CVEs and the resulting family of exploits are being referred to as 'wp2shell'.

We have deployed a network-level mitigation across shared hosting fleet on Thuirsday 23/07/2026 which blocks the affected REST API endpoint at the web server layer, protecting sites regardless of their WordPress version. The fix is available in WordPress 7.0.2 (and 6.8.6 / 6.9.5 for older branches - the vulnerability was introduced in 6.0). We recommend updating WordPress core at your earliest convenience.

In some cases the mitigation may affect certain WordPress admin features, most commonly the Appearance -> Widgets editor. If you experience issues with your WordPress dashboard, please open a support ticket and we can apply an exemption to updated Wordpress websites.

Need help? Talk to our experts...

Start a live chat, or call our friendly sales team on 0161 850 1172