Skip to content

Does Hawk Host provide protection against CVE-2026-63030 and CVE-2026-60137?

WordPress released 6.8.6, 6.9.5, and 7.0.2 on July 17th to protect against one critical and one high severity security issue. Less than 24 hours later, all Hawk Host cloud web hosting customers were protected against both vulnerabilities through Imunify360.

Hawk Host blocks attempts to exploit CVE-2026-63030 and CVE-2026-60137 using Imunify360. Imunify360 uses a combination of mod_security and global blocking strategies. Systems that attempt to exploit CVE-2026-63030 and CVE-2026-60137 may be blocked by all Hawk Host servers for a period of time.

If you utilize Cloudflare, they have also deployed web application firewall rules to protect against both CVE-2026-63030 and CVE-2026-60137.

Hawk Host highly recommends that you update to 6.8.6, 6.9.5, or 7.0.2 as soon as possible if you did not update automatically. You can update through the WordPress admin, using WP Toolkit, or the Softaculous WordPress Manager in cPanel.

Hawk Host will not protect you against CVE-2026-63030 and CVE-2026-60137 if you’ve disabled mod_security through cPanel or by .htaccess. If you have previously asked Hawk Host to remove your domain from Imunify360 protection, you will not be protected either.

CVE-2026-63030 is an unauthenticated remote code execution vulnerability in WordPress. An unauthenticated attacker can execute code using the WordPress REST API batch endpoint. The ability to execute code could compromise the WordPress installation.

Affected Versions:

  • 6.9.0 - 6.9.4
  • 7.0.0 - 7.0.1

CVE-2026-60137 is an SQL injection vulnerability in the author__not_in parameter of WP_Query

Affected Versions:

  • 6.8.0 - 6.8.5
  • 6.9.0 - 6.9.4
  • 7.0.0 - 7.0.1

Combining both CVE-2026-63030 and CVE-2026-60137 allows an exploit chain that is being referred to as wp2shell. The wp2shell only relies on the WordPress core and no further plugins, themes or authentication is required to perform the exploit chain.