mike
For older WordPress installations that cannot be upgraded at the moment, cPFence has released a free standalone plugin that blocks the malformed REST API batch requests used by the wp2shell (CVE-2026-63030) vulnerability.
Download the plugin:
https://gist.githubusercontent.com/cPFence/e574db54e99bb03bfe0d4217d32d8515/raw/cpfence-wp2shell-mitigation.php
If you are using cPFence, you can deploy the plugin ZIP across selected or all websites on all servers using cPFence’s bulk plugin installation tools.
DISCLAIMER
This plugin is a temporary mitigation, not a replacement for the official
WordPress security update. Back up your site and test this plugin in a
staging environment before using it in production.