News: Critical WordPress Security Update – Immediate Action Recommended
Two critical security vulnerabilities have been disclosed in WordPress Core, identified as CVE-2026-63030 and CVE-2026-60137. Together these vulnerabilities are commonly referred to as wp2shell.
When chained together, these vulnerabilities allow an unauthenticated remote attacker to achieve remote code execution (RCE) on a default WordPress installation. This could potentially lead to full compromise of a website and its hosting environment.
Who is affected?
Any website running a vulnerable version of WordPress Core may be affected.
We strongly recommend verifying the WordPress version running on all your websites.
Patched versions
The vulnerabilities have been fixed in:
* WordPress 7.1 Beta 2
* WordPress 7.0.2
* WordPress 6.9.5
* WordPress 6.8.6
Please update your website to one of these versions (or newer) as soon as possible.
Temporary mitigation
If an immediate update is not possible, consider the following temporary mitigations until the update can be installed:
* Block the following REST API endpoints at your web server or Web Application Firewall (WAF):
* /wp-json/batch/v1
* rest_route=/batch/v1
* Temporarily disable the WordPress REST API where possible.
These measures are temporary only and do not replace installing the official security update.
Vservs Recommendation
We strongly advise all WordPress users to verify whether their installations are vulnerable and apply the latest security updates immediately.
If your website is hosted on a Vservs Managed Hosting platform and you require assistance, our support team is ready to help.