CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

2026-07-19T19:23:42Zf8704926a1dd6ebeb0e40177c62f8084b8c35ac37de83b840876d73350134997
AWS persistenceAttackerKBCISA KEVCWE-502MetasploitMicrosoftPatch TuesdayRCESMA1000SSRFSharePointSonicWallWordPress REST APIactively exploitedcode injectiondeserializationhotfixpatchingremote code executionunauthenticatedvulnerability intelligencewordpresswp2shellzero-day

What happened

Rapid7 blog roundup (mid-July 2026) highlights multiple high-impact vulnerabilities and ecosystem updates. Key security advisories include CVE-2026-63030 (“wp2shell”), an unauthenticated RCE via the WordPress REST API batch endpoint affecting WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1; CVE-2026-58644, a SharePoint deserialization RCE (CVSS 9.8) with confirmed active exploitation and CISA KEV listing; and two actively exploited SonicWall SMA1000 zero-days—CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection/local escalation). The posts also cover Microsoft’s large July Patch Tuesday (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
f8704926a1dd6ebeb0e40177c62f8084b8c35ac37de83b840876d73350134997
Enrichment time
2026-07-19T19:23:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core · Baitaphish