Powering Over 30,000 Web Applications

Critical WordPress Security Advisory – Immediate Update Recommended

  • Monday, 20th July, 2026
  • 23:06pm

Greetings,

The WordPress Security Team has released emergency security updates addressing a critical vulnerability chain affecting WordPress core. The vulnerabilities are being actively targeted, and we strongly recommend that all customers running affected versions update their WordPress installations as soon as possible.

Affected Versions

If your website is running any of the following versions, please update immediately:

Current Version Update To
WordPress 7.0.0 – 7.0.1  7.0.2
WordPress 6.9.0 – 6.9.4 6.9.5
WordPress 6.8.x 6.8.6

The vulnerability chain, commonly referred to as wp2shell, combines:

  • CVE-2026-63030 – A flaw in the WordPress REST API batch endpoint that can be abused as an entry point for exploitation.
  • CVE-2026-60137 – A SQL Injection vulnerability within WordPress core.

When combined, these vulnerabilities may allow a remote attacker to compromise a vulnerable WordPress installation without requiring authentication.

Recommended Action

Please update WordPress core to the latest available version at your earliest convenience.

You can update by:

  • Logging in to your WordPress Dashboard and navigating to Dashboard → Updates, or
  • Using Softaculous, or WordPress Toolkit, or WordPress Manager from your hosting control panel, where available.

Updating WordPress core is the official and permanent resolution for these vulnerabilities.

HostPinnacle Security Response:

As part of our proactive security response, we have implemented multiple layers of protection across our hosting platform while customers complete their updates.

Enhanced WAF Protection

Our engineering team has deployed additional Web Application Firewall (WAF) rules across our hosting infrastructure to help detect and block known exploitation attempts targeting CVE-2026-63030, including the published attack techniques currently being observed.

Imunify360 Protection

All applicable hosting servers are protected by Imunify360.

Following this disclosure, we confirmed with the Imunify360 Security Team that the latest Imunify360 WAF ruleset includes protection against the currently known exploitation techniques targeting CVE-2026-63030. We have verified that our servers are operating with the latest available Imunify360 security rules and threat intelligence updates.

Continuous Monitoring

Our operations team is continuously monitoring server telemetry, web application firewall events, and security logs for indicators of compromise (IOCs), anomalous request patterns, and emerging exploitation attempts related to these vulnerabilities.

Important Note

The additional protections deployed across our platform are designed to reduce exposure while customers update their websites. However, they do not replace the official WordPress security update, which remains the only complete remediation for these vulnerabilities.

Need Assistance?

If you require assistance updating your WordPress installation or have any questions regarding this advisory, our support team will be happy to assist.

Thank you for helping keep your website secure.

HostPinnacle Security Team

« Back