सुरक्षा सलाह पर वापस जाएँ

wp2shell vulnerability CVE-2026-63030 and CVE-2026-60137

WordPress recently announced a few vulnerabilities that were fixed.

Critical 9.8 CVSS सक्रिय रूप से शोषित
cPanel Imunify360

डिफ़ॉल्ट अपडेट कमांड

Update WordPress core on every hosted site (wp core update). Imunify360 adds virtual patching for unpatched sites.

SharedLicense लाइसेंस के तहत इसका अर्थ

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel, Imunify360 software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel, Imunify360 under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

WordPress recently announced a few vulnerabilities that were fixed.

  • CVE-2026-63030
  • CVE-2026-60137

Impact

These vulnerabilities could allow an attacker to run SQL injections and execute remote code on the websites.

Call to action

It is recommended that you update to the updated versions of WordPress to address this vulnerability.

WordPress news details the updated version to be applied to websites.

  • 7.0.2 security release addresses a critical and high-severity issue

Supported mitigations

Emergency mitigations

CPANEL_WARN: The following may have an unexpected impact on the legitimate use of the sites and should only be used as an emergency or temporary measure until the sites can be updated. 

  • WP Plugin from wp2shell ( wp2shell )
  • Block “/wp-json/batch/v1” and “?rest_route=/batch/v1” with a custom WAF or Mod Security rule

Additional Resources

How can I add or edit a ModSecurity rule in WHM?

अक्सर पूछे जाने वाले प्रश्न

What is CVE-2026-63030?
A permission bypass in the WordPress REST API. Chained with CVE-2026-60137 it yields an unauthenticated remote code execution chain nicknamed "wp2shell", reported by Rapid7 and actively exploited in the wild.
Is CVE-2026-63030 being exploited in the wild?
Actively exploited — chaining the two flaws gives unauthenticated RCE; update WordPress core immediately.
How do I fix CVE-2026-63030?
Update cPanel, Imunify360 to the patched release.Then confirm the running version matches the patched release listed above.
Why does this advisory list several CVEs?
One vendor release fixed multiple vulnerabilities. This advisory covers CVE-2026-63030, CVE-2026-60137 — updating to the patched release resolves all of them at once.

अपने सिस्टम में भेद्यताओं की जाँच करें

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

अपना सिस्टम जाँचें