
Thank you for choosing AEDI.
A critical WordPress core vulnerability, wp2shell (CVE-2026-63030), has recently been disclosed.
This vulnerability may allow attackers to execute arbitrary code remotely and potentially compromise affected websites. If your WordPress installation is running an affected version, we strongly recommend updating it as soon as possible.
For Clients Enrolled in AEDI Website Regular Support (WordPress)
If you are subscribed to AEDI Website Regular Support (WordPress), the necessary security updates have already been completed by AEDI.
Clients using our SimpleTastes Affordable Website Service have also already been updated to address this vulnerability.
For Clients Who Are Not Enrolled in AEDI Website Regular Support (WordPress)
If AEDI developed your website but you are not subscribed to AEDI Website Regular Support (WordPress), please update your WordPress installation yourself.
Required Updates
Please update your WordPress installation to one of the following versions or later:
- WordPress 6.9.x → 6.9.5 or later
- WordPress 7.0.x → 7.0.2 or later
- WordPress 6.8.x → 6.8.6 or later
In addition, please update all installed plugins to their latest available versions.
Important Before Updating
Updating WordPress or plugins may cause compatibility issues with your theme or existing plugins.
Before performing any updates, please be sure to:
- Create a complete backup of your website and database.
- Update WordPress to the latest version.
- Update plugins one at a time, rather than updating all of them simultaneously.
- After each plugin update, verify that your website, contact forms, and other important functions continue to operate correctly.
If any issues occur, you should restore your website from the backup you created before beginning the update.
Disclaimer
If you are not enrolled in AEDI’s WordPress Maintenance Service, AEDI cannot accept responsibility for any issues or website malfunctions resulting from updates performed by the website owner.
Should you require assistance with troubleshooting, recovery, or repairing your website after an update, such work will be provided as a paid service.
Additional Information
For a technical explanation of this vulnerability, please refer to the following article:
Although many hosting providers have implemented temporary server-side mitigation measures, these are not a permanent solution.
Keeping both WordPress and all plugins up to date remains the most effective way to protect your website.
If you are unsure how to update WordPress or are uncomfortable performing the update yourself, please feel free to contact us.
AEDI remains committed to helping our clients keep their websites secure and up to date.