We're writing to make you aware of a critical security vulnerability affecting WordPress core, tracked as CVE-2026-63030 (also known as "wp2shell"). It is a pre-authentication remote code execution flaw: an attacker needs no login, no plugin, and no user interaction to exploit a vulnerable site. It is being actively exploited in the wild, and ...
Continue reading
Fraudulent "Message Restriction Portal" Emails
We have been made aware of phishing emails being sent to businesses claiming to be from Web Hosting Cymru.
These emails typically claim that messages have been placed on hold and ask recipients to click a "Release Messages" button.
These emails are NOT from Web Hosting Cymru.
Do NOT:
Click any ...
Continue reading