Affecting Other
-
Wordpress
-
23/07/2026 13:00
-
Last Updated 26/07/2026 17:51
Two critical WordPress core vulnerabilities have recently been disclosed. The first (CVE-2026-60137) is a SQL injection flaw in WordPress's query handling; the second (CVE-2026-63030) chains with it to allow unauthenticated remote code execution via the REST API. As an example of what this vulnerability allows, an attacker can create a new wordpress admin user into a website, thereby gaining full access at an administrative level to the website. Both are actively exploited in the wild and are listed on the CISA Known Exploited Vulnerabilities catalogue. The combination of these CVEs and the resulting family of exploits are being referred to as 'wp2shell'.
We have deployed a network-level mitigation across shared hosting fleet on Thuirsday 23/07/2026 which blocks the affected REST API endpoint at the web server layer, protecting sites regardless of their WordPress version. The fix is available in WordPress 7.0.2 (and 6.8.6 / 6.9.5 for older branches - the vulnerability was introduced in 6.0). We recommend updating WordPress core at your earliest convenience.
In some cases the mitigation may affect certain WordPress admin features, most commonly the Appearance -> Widgets editor. If you experience issues with your WordPress dashboard, please open a support ticket and we can apply an exemption to updated Wordpress websites.