Critical severity9.8CISA KEVNVD Advisory· Published Jul 17, 2026· Updated Jul 22, 2026
CVE-2026-63030
CVE-2026-63030
Description
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Affected products
4- osv-coords2 versions
>= 6.9.0, < 6.9.5+ 1 more
- (no CPE)range: >= 6.9.0, < 6.9.5
- (no CPE)range: >= 6.9.0, < 6.9.5
<6.9.5, <7.0.2+ 1 more
- (no CPE)range: <6.9.5, <7.0.2
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: >=6.9,<6.9.5
Patches
Vulnerability mechanics
References
3- github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662qnvdVendor Advisory
- wordpress.org/news/2026/07/wordpress-7-0-2-release/nvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
31- Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!Rapid7 Blog · Aug 28, 2026
- Metasploit Wrap Up: Lot of summer shells and fit http profilesRapid7 Blog · Aug 14, 2026
- WordPress 7.0.3 Released: 12 Vulnerabilities Found and FixedPatchstack Blog · Aug 6, 2026
- WP2Shell WordPress Exploit Technical Analysis and Real Attack DataWordfence Blog · Jul 29, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)Wordfence Blog · Jul 23, 2026
- Don’t swing at everythingCisco Talos Intelligence · Jul 23, 2026
- Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without AuthenticationThe Hacker News · Jul 22, 2026
- CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the WildCyber Security News · Jul 22, 2026
- Ninety minutes: watching attackers weaponize the WordPress core RCEPatchstack Blog · Jul 22, 2026
- Critical wp2shell WordPress flaws exploited to install webshellsBleepingComputer · Jul 21, 2026
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningThe Hacker News · Jul 21, 2026
- WordPress: 2 Actively-Exploited Flaws Added to CISA KEVVypr Intelligence · Jul 21, 2026
- Attackers pummel critical WordPress vuln to create all sorts of mischiefThe Register Security · Jul 20, 2026
- wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a DecadeWordfence Blog · Jul 20, 2026
- 'WP2Shell' Opens Millions of WordPress Sites to Remote TakeoverDark Reading · Jul 20, 2026
- WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)SANS Internet Storm Center · Jul 20, 2026
- Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation DetailsCyber Security News · Jul 20, 2026
- Researchers Build WordPress Exploit Using OpenAI's GPTInfosecurity Magazine · Jul 20, 2026
- wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress CoreTenable Blog · Jul 20, 2026
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThe Hacker News · Jul 20, 2026
- 20th July – Threat Intelligence ReportCheck Point Research · Jul 20, 2026
- WP2Shell WordPress Vulnerabilities Exploited in the WildSecurityWeek · Jul 20, 2026
- Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 StoriesCyber Security News · Jul 19, 2026
- WordPress Core "wp2shell" RCE flaws get public exploits, patch nowBleepingComputer · Jul 18, 2026
- New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch ReleasedCyber Security News · Jul 18, 2026
- PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability ChainWordfence Blog · Jul 17, 2026
- CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress CoreRapid7 Blog · Jul 17, 2026
- Cloudflare WAF protects WordPress applications from two high-severity vulnerabilitiesCloudflare Blog · Jul 17, 2026
- Unauthenticated SQL Injection in WordPress Core Fixed in 7.0.2Patchstack Blog · Jul 17, 2026
- WordPress 7.0.2 ReleaseWordPress Core Security · Jul 17, 2026
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA Alerts