Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for WordPress wp2shell CVE-2026-63030 pre-auth RCE vulnerability

A critical vulnerability in WordPress core — dubbed wp2shell (CVE-2026-63030) — lets an unauthenticated attacker take full control of any affected WordPress site. No login, no plugins, no special configuration required. A working proof-of-concept exploit is now public.

What happened

Security researchers discovered a flaw in WordPress’s REST API batch endpoint that chains a route-confusion bug with SQL injection to achieve remote code execution. WordPress.org released emergency patches (versions 7.0.2, 6.9.5, and 6.8.6) on 17 July and has taken the unusual step of force-pushing updates to all affected sites via auto-update. Versions 6.9.0–6.9.4, 7.0.0–7.0.1, and the 7.1 beta are all vulnerable to the full RCE chain.

Why it matters for Australian businesses

WordPress powers a huge share of Australian small business websites — from local cafés and trades to professional services firms. Across our client base in Sydney, the Central West, and Brisbane, we regularly see sites running on managed hosting where auto-updates are delayed by staging workflows or compatibility checks. If your hosting provider queues updates rather than applying them immediately, your site could be sitting exposed right now with a public exploit in circulation. This isn’t a plugin issue you can work around — it’s in WordPress core itself.

What to do

Check your WordPress version immediately. If you’re not on 7.0.2 (or 6.9.5/6.8.6 for older branches), update now. If you can’t update straight away, block the /wp-json/batch/v1 endpoint at your firewall or WAF as a temporary measure. Ask your hosting provider to confirm the patch has been applied.

If you’re unsure whether your WordPress site is patched, get in touch — our team can check and lock it down for you. We also offer ongoing managed IT support that includes keeping your web presence patched and secure.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →