WordPressの脆弱性「wp2shell」に関する当社管理サイトの安全確認と対応について

2026年7月17日、WordPress本体において深刻度「緊急」の脆弱性(CVE-2026-63030 / CVE-2026-60137、通称「wp2shell」)が公開されました。特定のバージョン(6.9.0〜6.9.4 および 7.0.0〜7.0.1)で稼働しているサイトでは、認証なしに外部からサーバー上で任意のコードを実行されるおそれがあるというものです。

この公開を受け、当社で制作・管理しているすべてのWebサイトを対象に、WordPressの稼働バージョンの確認と安全確認を実施いたしました。

確認の結果、当社管理サイトに該当バージョンで稼働していたものはなく、本脆弱性による攻撃が成立する状態になかったことを確認しております。あわせて、各サイトのWordPressを修正版へ更新する対応も完了しています。

当社では今後も、脆弱性情報の把握と管理サイトの保守対応を継続してまいります。ご不明な点がございましたら、お気軽にお問い合わせください。

About the author

Kazuhito Naozuka Representative Director / Web Director / Programmer

Based in Saga City, supporting web strategy for small and medium-sized businesses and sole proprietors. Handling everything from website creation to SaaS development, SEO optimization, and ad management across the digital domain. Our mission is to accelerate the growth of regional businesses through "technical expertise × strategic proposals." We have been involved in numerous projects to date.