NODE+ — Security Advisory Email CVE-2026-63030 / WordPress Core Suggested subject: [Critical] Segera Update WordPress — CVE-2026-63030 Suggested preheader: Kerentanan RCE tanpa autentikasi memengaruhi WordPress 6.9.0–6.9.4 dan 7.0.0–7.0.1. Before sending: 1. Upload every image in the assets folder to your email platform, then replace the relative image paths with public HTTPS URLs or the platform's hosted-image paths. 2. Replace {{node_contact_url}} with the NODE+ contact or consultation URL. 3. Map {{unsubscribe_url}} to the email platform's unsubscribe merge tag. 4. Send a test to Outlook desktop, Gmail desktop, and Gmail mobile before launch. Verified security summary (source updated 20 July 2026): - CVE-2026-63030 is classified Critical; Rapid7 reported an assigned CVSS score of 7.5. - The issue can enable unauthenticated remote code execution via WordPress Core. - Affected: WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. - Fixed: WordPress 6.9.5 and 7.0.2; WordPress 7.1 Beta 2 also contains a fix. - Immediate upgrade is recommended; workarounds are not recommended. Primary source: https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core/ Official WordPress release: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ Brand reference: NODE+ primary blue: #1e4594 Hero visual prompt and generation method: Generated with the built-in image generation tool using the provided screenshot as a style reference. The prompt requested a predominantly light enterprise cybersecurity banner with a protected website, shield, network nodes, NODE+ blue, navy, restrained critical-red accents, no text, and no logos.