Two vulnerabilities allowing remote code execution have been recently identified in WordPress.
Given their severity, we have taken measures to prevent our webhosting customers' website from being exploited.
This might break some websites features; namely requests whose path contains wp-json/batch/v1 or rest_route=/batch/v1 will return a 403 error code.
If you run WordPress on your website, please upgrade to version 6.9.5 or 7.0.2 as soon as possible.
This link provides more information on the vulnerability itself: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html