Two vulnerabilities allowing remote code execution have been recently identified in WordPress.
Given their severity, we have taken measures to prevent our webhosting customers' website from being exploited.
This might break some websites features; namely requests whose path contains wp-json/batch/v1 or rest_route=/batch/v1 will return a 403 error code.
If you run WordPress on your website, please upgrade to version 6.9.5 or 7.0.2 as soon as possible.
This link provides more information on the vulnerability itself: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
Further research has shown that attackers only reached our servers after 18-07-2026, 00:00.
We also learned from many customers that auto-updates for their website already took place in the evening of 17-07. If the update took place before attackers reached our platform, this means your website has not been vulnerable.
If you check your Wordpress logs and you find that auto-updates to WordPress version 7.02 indeed already took place on 17-7 in the evening, chances of your site being hacked are minimal.
At this moment, we are investigating the impact this vulnerability had on our customer's websites.
Yesterday (19-07), the vulnerability has been sealed through a temporary measure on our side, but a number of Wordpress installations has been vulnerable for some time. We will inform the affected customers with by e-mail later today.
If you did not receive an e-mail by tomorrow morning, we do not believe your account to be at risk. However, we still advise to make sure your Wordpress is up-to-date with the latest version.
If you are running Wordpress on a VPS, we can not verify if your Wordpress has been vulnerable.