CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
2026-07-20T07:23:49Z•809d38279225e53f6f527f0d78dd6699d24a78f7aff340f70ea89eaba5ec0825
CISA KEVCVE-2026-15409CVE-2026-15410CVE-2026-55040CVE-2026-58644CVE-2026-63030Microsoft SharePointPatch TuesdayREST APISSRFSonicWall SMA1000WordPresscode injectionexploitpatchingremote code executionvulnerabilitywp2shellzero-day
What happened
Rapid7 posts covering multiple high-impact 2026 vulnerabilities: CVE-2026-63030 (“wp2shell”) is an unauthenticated RCE in WordPress Core via the REST API batch endpoint (affects WP 6.9.0–6.9.4 and 7.0.0–7.0.1; GHSA-classified Critical, CVSS 7.5). Microsoft SharePoint suffers an unauthenticated deserialization RCE (CVE-2026-58644, CVSS 9.8) that is actively exploited and added to CISA KEV. SonicWall SMA1000 appliances have two actively exploited zero-days: CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code-injection/local privilege escalation); customers are urged to apply hotfixes. July
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 809d38279225e53f6f527f0d78dd6699d24a78f7aff340f70ea89eaba5ec0825
- Enrichment time
- 2026-07-20T07:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.