A critical vulnerability in WordPress core — dubbed wp2shell (CVE-2026-63030) — lets an unauthenticated attacker take full control of any affected WordPress site. No login, no plugins, no special configuration required. A working proof-of-concept exploit is now public.
What happened
Security researchers discovered a flaw in WordPress’s REST API batch endpoint that chains a route-confusion bug with SQL injection to achieve remote code execution. WordPress.org released emergency patches (versions 7.0.2, 6.9.5, and 6.8.6) on 17 July and has taken the unusual step of force-pushing updates to all affected sites via auto-update. Versions 6.9.0–6.9.4, 7.0.0–7.0.1, and the 7.1 beta are all vulnerable to the full RCE chain.
Why it matters for Australian businesses
WordPress powers a huge share of Australian small business websites — from local cafés and trades to professional services firms. Across our client base in Sydney, the Central West, and Brisbane, we regularly see sites running on managed hosting where auto-updates are delayed by staging workflows or compatibility checks. If your hosting provider queues updates rather than applying them immediately, your site could be sitting exposed right now with a public exploit in circulation. This isn’t a plugin issue you can work around — it’s in WordPress core itself.
What to do
Check your WordPress version immediately. If you’re not on 7.0.2 (or 6.9.5/6.8.6 for older branches), update now. If you can’t update straight away, block the /wp-json/batch/v1 endpoint at your firewall or WAF as a temporary measure. Ask your hosting provider to confirm the patch has been applied.
If you’re unsure whether your WordPress site is patched, get in touch — our team can check and lock it down for you. We also offer ongoing managed IT support that includes keeping your web presence patched and secure.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
