Security confirmation and response measures for sites we manage regarding the WordPress vulnerability "wp2shell"
On July 17, 2026, WordPress disclosed a critical vulnerability in its core (CVE-2026-63030 / CVE-2026-60137, nicknamed "wp2shell"). Sites running specific versions (6.9.0 to 6.9.4 and 7.0.0 to 7.0.1) may be vulnerable to arbitrary code execution on the server from external sources without authentication.
Following this disclosure, we conducted a comprehensive review of all websites we produce and manage, confirming the WordPress version in use and verifying security status.
Our investigation confirmed that none of our managed sites were running vulnerable versions, and therefore were not susceptible to attacks exploiting this vulnerability. We have also completed updates of WordPress on all sites to patched versions.
R-LABS Inc. will continue to monitor vulnerability information and maintain our managed sites going forward. Please feel free to contact us if you have any questions.