WordPress Zero-Day Lets Attackers Hijack Sites: Patch Now
A critical vulnerability in WordPress core, dubbed wp2shell (CVE-2026-63030), lets an unauthenticated attacker take full control of any affected WordPress site. No login, no plugins, no special configuration required. A working proof-of-concept exploit is now public.
What Happened
Security researchers discovered a flaw in WordPress's REST API batch endpoint that chains a route-confusion bug with SQL injection to achieve remote code execution. WordPress.org released emergency patches (versions 7.0.2, 6.9.5, and 6.8.6) on 17 July and has taken the unusual step of force-pushing updates to all affected sites via auto-update. Versions 6.9.0 to 6.9.4, 7.0.0 to 7.0.1, and the 7.1 beta are all vulnerable to the full RCE chain.
Why It Matters for Australian Businesses
WordPress powers a huge share of Australian small business websites: from local cafés and trades to professional services firms. Across our client base in Sydney, the Central West, and Brisbane, we regularly see sites running on managed hosting where auto-updates are delayed by staging workflows or compatibility checks. If your hosting provider queues updates rather than applying them immediately, your site could be sitting exposed right now with a public exploit in circulation. This isn't a plugin issue you can work around. It's in WordPress core itself.
What to Do
- Check your WordPress version immediately in Dashboard → Updates.
- Update to version 7.0.2 (or 6.9.5/6.8.6 if you're on an older branch) before doing anything else.
- If you can't update straight away, block the
/wp-json/batch/v1endpoint at your firewall or WAF as a temporary measure. - Ask your hosting provider to confirm the patch has been applied, even if auto-update is enabled. Staging workflows can delay it.
- If you're unsure whether your site is patched, get in touch; our team can check and lock it down for you.
We also offer ongoing managed IT support that includes keeping your web presence patched and secure, so your team doesn't need to track advisories like this one.
Sources
- wp2shell RCE Vulnerability, Cybersecurity News
- WordPress.org Security Advisory: CVE-2026-63030 (versions 7.0.2, 6.9.5, 6.8.6, released 17 July 2026)
Written by Caleb Attard, Head of Business Operations, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.
Frequently Asked Questions: WordPress Zero-Day CVE-2026-63030
/wp-json/batch/v1 endpoint at your firewall or web application firewall (WAF) as a temporary mitigation. This closes the specific attack vector while you arrange the patch. Contact your hosting provider or IT team to apply this rule, then update WordPress as soon as you can. The temporary mitigation is not a permanent fix.
Not Sure If Your WordPress Site Is Patched?
Our team can check your site, apply the patch, and review for signs of compromise. We also offer managed IT support that keeps your web presence secure ongoing.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
