We're writing to make you aware of a critical security vulnerability affecting WordPress core, tracked as CVE-2026-63030 (also known as "wp2shell"). It is a pre-authentication remote code execution flaw: an attacker needs no login, no plugin, and no user interaction to exploit a vulnerable site. It is being actively exploited in the wild, and public exploit code is circulating.
Affected versions:
- WordPress 6.9.0 through 6.9.4
- WordPress 7.0.0 through 7.0.1
Patched versions:
- 6.9.5
- 7.0.2
What we recommend you do:
1. Check your WordPress version under Dashboard > Updates. If you're on an affected version, update to 6.9.5 / 7.0.2 or later immediately.
2. Confirm automatic updates are enabled so future security releases apply.
3. Verify the update completed successfully after it runs.
We also recommend enabling automatic updates for plugins and themes as best practice - as these are frequent routes for security exploits.
If you have questions about your specific setup then our support team is here to help — just raise a support ticket.
Best regards,
Web Hosting Cymru
Powered by WHMCompleteSolution