Does Hawk Host provide protection against CVE-2026-63030 and CVE-2026-60137?
WordPress released 6.8.6, 6.9.5, and 7.0.2 on July 17th to protect against one critical and one high severity security issue. Less than 24 hours later, all Hawk Host cloud web hosting customers were protected against both vulnerabilities through Imunify360.
Imunify360 Protection
Section titled “Imunify360 Protection”Hawk Host blocks attempts to exploit CVE-2026-63030 and CVE-2026-60137 using Imunify360. Imunify360 uses a combination of mod_security and global blocking strategies. Systems that attempt to exploit CVE-2026-63030 and CVE-2026-60137 may be blocked by all Hawk Host servers for a period of time.
Cloudflare Protection
Section titled “Cloudflare Protection”If you utilize Cloudflare, they have also deployed web application firewall rules to protect against both CVE-2026-63030 and CVE-2026-60137.
Best Practices
Section titled “Best Practices”Hawk Host highly recommends that you update to 6.8.6, 6.9.5, or 7.0.2 as soon as possible if you did not update automatically. You can update through the WordPress admin, using WP Toolkit, or the Softaculous WordPress Manager in cPanel.
When are you not protected?
Section titled “When are you not protected?”Hawk Host will not protect you against CVE-2026-63030 and CVE-2026-60137 if you’ve disabled mod_security through cPanel or by .htaccess. If you have previously asked Hawk Host to remove your domain from Imunify360 protection, you will not be protected either.
Background
Section titled “Background”CVE-2026-63030
Section titled “CVE-2026-63030”CVE-2026-63030 is an unauthenticated remote code execution vulnerability in WordPress. An unauthenticated attacker can execute code using the WordPress REST API batch endpoint. The ability to execute code could compromise the WordPress installation.
Affected Versions:
- 6.9.0 - 6.9.4
- 7.0.0 - 7.0.1
CVE-2026-60137
Section titled “CVE-2026-60137”CVE-2026-60137 is an SQL injection vulnerability in the author__not_in parameter of WP_Query
Affected Versions:
- 6.8.0 - 6.8.5
- 6.9.0 - 6.9.4
- 7.0.0 - 7.0.1
Combined Impact
Section titled “Combined Impact”Combining both CVE-2026-63030 and CVE-2026-60137 allows an exploit chain that is being referred to as wp2shell. The wp2shell only relies on the WordPress core and no further plugins, themes or authentication is required to perform the exploit chain.