wp2shell vulnerability CVE-2026-63030 and CVE-2026-60137
WordPress recently announced a few vulnerabilities that were fixed.
Default Update CMD
Update WordPress core on every hosted site (wp core update). Imunify360 adds virtual patching for unpatched sites.
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a vulnerability in cPanel, Imunify360 software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel, Imunify360 under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.
Situation
WordPress recently announced a few vulnerabilities that were fixed.
- CVE-2026-63030
- CVE-2026-60137
Impact
These vulnerabilities could allow an attacker to run SQL injections and execute remote code on the websites.
Call to action
It is recommended that you update to the updated versions of WordPress to address this vulnerability.
WordPress news details the updated version to be applied to websites.
- 7.0.2 security release addresses a critical and high-severity issue
Supported mitigations
- Imunify360 (WAF rules 8.33, 8.32 – WPT-2656 WordPress Core: WAF protection against SQL injection and unauthenticated remote code execution (CVE-2026-60137, CVE-2026-63030)
- WordFence ( Premium, Care, and Response customers received on Jul 17th – Free customers receive the update by August 16th, 2026 )
- CloudFlare ( Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities )
Emergency mitigations
CPANEL_WARN: The following may have an unexpected impact on the legitimate use of the sites and should only be used as an emergency or temporary measure until the sites can be updated.
- WP Plugin from wp2shell ( wp2shell )
- Block “/wp-json/batch/v1” and “?rest_route=/batch/v1” with a custom WAF or Mod Security rule
Additional Resources
Frequently Asked Questions
What is CVE-2026-63030?
Is CVE-2026-63030 being exploited in the wild?
How do I fix CVE-2026-63030?
Why does this advisory list several CVEs?
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System