CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
2026-07-18T19:23:41Z•551411dd4f18df779afbc00d4a352f1de81176c0b56f14ac07f49783bcb23f07
active-exploitationattackerkb-sunsetaws-persistencecisa-kevdeserializationmetasploitpatchingremote code executionsharepointsma1000sonicwallssrfunauthenticatedvulnerability-managementwordpresswp2shellzero-day
What happened
Rapid7 published multiple security advisories and analyses covering several high-impact vulnerabilities and ecosystem updates. Key issues include CVE-2026-63030 (wp2shell) — an unauthenticated RCE in WordPress Core via the REST API batch endpoint (officially classified Critical); CVE-2026-58644 — an unauthenticated deserialization RCE in on‑premises Microsoft SharePoint Server (CVSS 9.8) confirmed exploited in the wild and added to CISA KEV; and two actively exploited SonicWall SMA1000 zero-days (CVE-2026-15409, SSRF, CVSS 10.0; and CVE-2026-15410, code injection/local privilege escalation). R
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 551411dd4f18df779afbc00d4a352f1de81176c0b56f14ac07f49783bcb23f07
- Enrichment time
- 2026-07-18T19:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.