CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

2026-07-20T07:23:49Z809d38279225e53f6f527f0d78dd6699d24a78f7aff340f70ea89eaba5ec0825
CISA KEVCVE-2026-15409CVE-2026-15410CVE-2026-55040CVE-2026-58644CVE-2026-63030Microsoft SharePointPatch TuesdayREST APISSRFSonicWall SMA1000WordPresscode injectionexploitpatchingremote code executionvulnerabilitywp2shellzero-day

What happened

Rapid7 posts covering multiple high-impact 2026 vulnerabilities: CVE-2026-63030 (“wp2shell”) is an unauthenticated RCE in WordPress Core via the REST API batch endpoint (affects WP 6.9.0–6.9.4 and 7.0.0–7.0.1; GHSA-classified Critical, CVSS 7.5). Microsoft SharePoint suffers an unauthenticated deserialization RCE (CVE-2026-58644, CVSS 9.8) that is actively exploited and added to CISA KEV. SonicWall SMA1000 appliances have two actively exploited zero-days: CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code-injection/local privilege escalation); customers are urged to apply hotfixes. July

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
809d38279225e53f6f527f0d78dd6699d24a78f7aff340f70ea89eaba5ec0825
Enrichment time
2026-07-20T07:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.