
Plugin active on the Plugins screen with core status.
Was your site hacked? Did you get a “password changed” email without requesting a reset? You may be a victim of the wp2shell attack — one of the most serious security issues in recent years.
Batch REST Guard is a free security plugin that protects your website from the wp2shell exploit chain (CVE-2026-63030 + CVE-2026-60137). Attackers use this vulnerability to break into sites without a password, create hidden administrator accounts, install backdoor plugins, and change your admin password — all through the REST API batch endpoint.
/wp-json/batch/v1 and ?rest_route=/batch/v1 (including POST body bypasses that fool some WAF rules).w2s_*, wp2_*, wpsvc_*) and fake plugins (site-tweaks-…, admin-utils-…, content-tools-… and similar random names).Wp2shell is an unauthenticated remote code execution (RCE) attack against the WordPress REST API batch endpoint. It was actively exploited in the wild in 2026. Attackers can:
w2s_… or wp2_…).Updating core is the complete fix. This plugin adds an essential extra layer and helps you spot leftover malware after a cleanup.
Developed by 365dizajn — web design and hosting security.