CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

2026-07-19T07:23:43Zdf8b2216af0659788b929a759353c26c5b34f401297892c6768f7e181a7be596
CISA KEVCVE-2026-15409CVE-2026-15410CVE-2026-58644CVE-2026-63030Microsoft SharePointPatch TuesdayREST APISMA1000SSRFSonicWallWordPressactive exploitationdeserializationhotfix recommendedunauthenticated RCEvulnerability managementwp2shellzero-day

What happened

Multiple high-impact, actively exploited vulnerabilities disclosed in July 2026: CVE-2026-63030 (“wp2shell”) is an unauthenticated remote code execution in WordPress Core via the REST API batch endpoint (affects WP 6.9.0–6.9.4 and 7.0.0–7.0.1). CVE-2026-58644 is a critical deserialization RCE in on-premises Microsoft SharePoint Server (CVSS 9.8) with confirmed exploitation and inclusion in CISA’s KEV catalog. Rapid7 MDR also reported active exploitation of SonicWall SMA1000 zero-days: CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection/local escalation). July Patch Tuesday also

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
df8b2216af0659788b929a759353c26c5b34f401297892c6768f7e181a7be596
Enrichment time
2026-07-19T07:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.