[Notice] [Important] Advisory regarding the critical WordPress vulnerability (wp2shell / CVE-2026-63030)
Thank you very much for using our services.
We would like to inform you that a critical vulnerability has been disclosed in the core functionality of the Content Management System "WordPress." This vulnerability could potentially lead to unauthorized code execution by third parties (site hijacking) without requiring authentication (CVE-2026-63030, commonly known as "wp2shell"). It also includes a SQL injection vulnerability that can be exploited in conjunction with it (CVE-2026-60137).
This vulnerability is unauthenticated/login unnecessary, and affects all environments using the affected versions of WordPress, regardless of installed plugins or themes. If you use WordPress, please check this immediately.
Affected Versions
- WordPress 6.9.0 ~ 6.9.4
- WordPress 7.0.0 ~ 7.0.1
- WordPress 6.8.0 ~ 6.8.5 (Subject to the linked SQL injection vulnerability)
Request to Customers (Permanent Countermeasure)
Please update your current WordPress installation promptly to the following patched versions or later.
- 6.9.x → 6.9.5 or later
- 7.0.x → 7.0.2 or later
- 6.8.x → 6.8.6 or later
※Even if automatic updates are enabled, please confirm that the update has actually completed in the administration screen.
Regarding Temporary Measures by Server Providers
Some rental server providers have implemented temporary measures to block communication to the REST API batch endpoint (/wp-json/batch/v1), which is a potential attack vector. Due to this, plugins, themes, external integrations, or custom functions that utilize this API may temporarily function abnormally. Please check the announcements from your contracted server provider for details.
For Customers Using Our CMS (VosCMS)
Sites built with our proprietary CMS, "VosCMS," are not affected by this WordPress vulnerability. You can use them with peace of mind. If you have any questions regarding updating WordPress sites or security, please feel free to contact us.
【Reference (External Link)】
・Star Rental Server Notice: https://www.star.ne.jp/news/detail.php?view_id=14373
・Please also check official announcements from WordPress, JVN, NVD, etc.
July 23, 2026
The Boss ECO Research Institute Co., Ltd.