Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for WordPress wp2shell CVE-2026-63030 pre-auth RCE vulnerability

WordPress Zero-Day Lets Attackers Hijack Sites: Patch Now

A critical vulnerability in WordPress core, dubbed wp2shell (CVE-2026-63030), lets an unauthenticated attacker take full control of any affected WordPress site. No login, no plugins, no special configuration required. A working proof-of-concept exploit is now public.

Critical advisory: unauthenticated remote code execution (RCE) with a public proof-of-concept exploit in circulation. Patch immediately or apply the temporary WAF mitigation below.

What Happened

Security researchers discovered a flaw in WordPress's REST API batch endpoint that chains a route-confusion bug with SQL injection to achieve remote code execution. WordPress.org released emergency patches (versions 7.0.2, 6.9.5, and 6.8.6) on 17 July and has taken the unusual step of force-pushing updates to all affected sites via auto-update. Versions 6.9.0 to 6.9.4, 7.0.0 to 7.0.1, and the 7.1 beta are all vulnerable to the full RCE chain.

Why It Matters for Australian Businesses

WordPress powers a huge share of Australian small business websites: from local cafés and trades to professional services firms. Across our client base in Sydney, the Central West, and Brisbane, we regularly see sites running on managed hosting where auto-updates are delayed by staging workflows or compatibility checks. If your hosting provider queues updates rather than applying them immediately, your site could be sitting exposed right now with a public exploit in circulation. This isn't a plugin issue you can work around. It's in WordPress core itself.

What to Do

  • Check your WordPress version immediately in Dashboard → Updates.
  • Update to version 7.0.2 (or 6.9.5/6.8.6 if you're on an older branch) before doing anything else.
  • If you can't update straight away, block the /wp-json/batch/v1 endpoint at your firewall or WAF as a temporary measure.
  • Ask your hosting provider to confirm the patch has been applied, even if auto-update is enabled. Staging workflows can delay it.
  • If you're unsure whether your site is patched, get in touch; our team can check and lock it down for you.

We also offer ongoing managed IT support that includes keeping your web presence patched and secure, so your team doesn't need to track advisories like this one.

Related guide: Cybersecurity for Sydney SMBs: our complete guide to protecting your business from cyber threats.

Sources

Written by Caleb Attard, Head of Business Operations, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.


Frequently Asked Questions: WordPress Zero-Day CVE-2026-63030

wp2shell (CVE-2026-63030) is a critical vulnerability in WordPress core's REST API batch endpoint. It chains a route-confusion bug with SQL injection to achieve unauthenticated remote code execution, meaning an attacker can take full control of an affected site without needing login credentials, installed plugins, or any special configuration. A working proof-of-concept exploit is publicly available.
The full RCE chain affects WordPress 6.9.0 to 6.9.4, 7.0.0, 7.0.1, and the 7.1 beta. Patched versions are 7.0.2, 6.9.5, and 6.8.6. WordPress.org is force-pushing updates to all affected sites, but managed hosting environments and staging workflows may delay this. Always verify your version in Dashboard → Updates rather than assuming auto-update has run.
If an immediate update isn't possible, block the /wp-json/batch/v1 endpoint at your firewall or web application firewall (WAF) as a temporary mitigation. This closes the specific attack vector while you arrange the patch. Contact your hosting provider or IT team to apply this rule, then update WordPress as soon as you can. The temporary mitigation is not a permanent fix.
Common signs of compromise include unexpected admin accounts, modified core files, unfamiliar cron jobs, unusual outbound traffic, or malware warnings from Google Search Console. However, a sophisticated attacker may leave no obvious trace. If you're concerned, contact a professional for a site integrity check before patching, as the patch alone does not remove a backdoor that's already been installed. All IT Services can assess and remediate affected sites.

Not Sure If Your WordPress Site Is Patched?

Our team can check your site, apply the patch, and review for signs of compromise. We also offer managed IT support that keeps your web presence secure ongoing.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →