Skip to main content

WordPress Security — Fukuoka, Japan

WordPress Emergency Security Check — the first 15 minutes when you fear a takeover

In July 2026 a critical vulnerability in WordPress core was disclosed, and real-world attacks have been confirmed. We have distilled "Is my site safe?" into steps you can follow without technical expertise. Brought to you by RINSAI TECH Inc., a software development company in Fukuoka.

① What is happening (the facts)

On 17 July 2026, versions 6.9.5 / 7.0.2 were released, fixing two WordPress core vulnerabilities (CVE-2026-63030 and CVE-2026-60137, together known as "wp2shell"). By combining route confusion in the REST API batch endpoint (/wp-json/batch/v1) with SQL injection, an attacker can execute code on the server from the outside without any login credentials (unauthenticated RCE) — and sites left in a standard configuration are affected.

  • Affected versions: 6.9.0–6.9.4 and 7.0.0–7.0.1
  • Fixed versions: 6.9.5 / 7.0.2 (released 17 July 2026)
  • On 21 July 2026, both were added to the U.S. CISA Known Exploited Vulnerabilities Catalog (KEV). In other words, this is not a theoretical risk — it is publicly confirmed to be used in real attacks.

WordPress.org has pushed a forced automatic update to the affected versions. However, if you have disabled automatic updates or heavily customized your configuration, it may not have been applied. Do not assume "it must have been fixed automatically" — check the actual version of your own site.

② Is your site affected — a 15-minute self-diagnosis checklist

The following items can be checked without special knowledge by anyone who can log in to the admin dashboard. The goal is not to hunt for "evidence" of a breach, but to decide whether you can say your site is safe.

  1. 1. Check your WordPress version (about 3 min)

    Log in to the admin dashboard and check the version under Dashboard → Updates. If it is 6.9.5 or 7.0.2 or higher, the core is patched. If it is still 6.9.0–6.9.4 / 7.0.0–7.0.1, update immediately.

  2. 2. Check whether automatic updates are enabled (about 2 min)

    On the same Updates screen, check the automatic-update setting. If it is disabled, an emergency fix like this one may not have reached you. We recommend enabling it.

  3. 3. Look for unfamiliar administrator accounts or plugins (about 4 min)

    In the Users list, check for any administrator-level account you do not recognize. In the Plugins list, check for anything you did not install or that was recently activated on its own. If you find even one, suspect a possible compromise.

  4. 4. Check recent file modification dates (about 4 min)

    If you can access FTP or the server's file manager, check modification dates on wp-content and similar, and look for any recent changes you do not recognize (if you cannot access these, feel free to skip this step).

  5. 5. Check whether you have a backup and when it was taken (about 2 min)

    Whether you have a "point you can return to" in an emergency makes a huge difference to what happens next. Check whether you have a backup and the date it was last taken.

An honest note: even if this check finds nothing wrong, it does not prove there was no breach. Conversely, if you find even one anomaly, do not just update — we recommend consulting an expert.

③ If you cannot handle it yourself

In practice, we believe inquiries in situations like these are not uncommon.

  • You cannot reach the company that built or manages your site, or the contract has ended
  • You do not know the admin login credentials, or they were never handed over
  • You get an error when you try to update, or the theme and plugins are so old that updating is scary
  • The checklist made you find a suspicious account or file, but you do not know what to do next

In cases like these, doing nothing is what increases the risk the most. When a compromise is suspected, before it spreads into further tampering or affects your visitors, it is worth asking a third party to at least assess the current state.

④ So it does not end as a stopgap — about ongoing management

Emergency responses like this one repeat themselves if you treat them as "update and done." The underlying problem is that there is no one continuously looking after the site.

RINSAI TECH Inc. (Fukuoka) provides ongoing management (monthly maintenance) for websites and servers, including WordPress. With a small, highly efficient team that leverages AI, we handle the "unglamorous but must-never-stop" work of version monitoring, security updates, and backups. We can also issue qualified invoices (インボイス).

Start with a free assessment of your current state. We are happy to help even if your question is simply "I got stuck partway through the checklist."

Request a free consultation & assessment →

If the form is inconvenient, contact us directly at [email protected]. We reply within one business day.