Back to Security Advisories

wp2shell vulnerability CVE-2026-63030 and CVE-2026-60137

WordPress recently announced a few vulnerabilities that were fixed.

Critical
cPanel Imunify360

Default Update CMD

sudo /scripts/upcp --force

Situation

WordPress recently announced a few vulnerabilities that were fixed.

  • CVE-2026-63030
  • CVE-2026-60137

Impact

These vulnerabilities could allow an attacker to run SQL injections and execute remote code on the websites.

Call to action

It is recommended that you update to the updated versions of WordPress to address this vulnerability.

WordPress news details the updated version to be applied to websites.

  • 7.0.2 security release addresses a critical and high-severity issue

Supported mitigations

Emergency mitigations

CPANEL_WARN: The following may have an unexpected impact on the legitimate use of the sites and should only be used as an emergency or temporary measure until the sites can be updated. 

  • WP Plugin from wp2shell ( wp2shell )
  • Block “/wp-json/batch/v1” and “?rest_route=/batch/v1” with a custom WAF or Mod Security rule

Additional Resources

How can I add or edit a ModSecurity rule in WHM?

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

Check Your System