Mitigation of WordPress vulnerabilities Sunday 19th July 2026 12:35:00


Two vulnerabilities allowing remote code execution have been recently identified in WordPress.

Given their severity, we have taken measures to prevent our webhosting customers' website from being exploited. This might break some websites features; namely requests whose path contains wp-json/batch/v1 or rest_route=/batch/v1 will return a 403 error code.

If you run WordPress on your website, please upgrade to version 6.9.5 or 7.0.2 as soon as possible.

This link provides more information on the vulnerability itself: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html

At this moment, we are investigating the impact this vulnerability had on our customer's websites.

Yesterday (19-07), the vulnerability has been sealed through a temporary measure on our side, but a number of Wordpress installations has been vulnerable for some time. We will inform the affected customers with by e-mail later today.

If you did not receive an e-mail by tomorrow morning, we do not believe your account to be at risk. However, we still advise to make sure your Wordpress is up-to-date with the latest version.

If you are running Wordpress on a VPS, we can not verify if your Wordpress has been vulnerable.