CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
2026-07-19T19:23:42Z•f8704926a1dd6ebeb0e40177c62f8084b8c35ac37de83b840876d73350134997
AWS persistenceAttackerKBCISA KEVCWE-502MetasploitMicrosoftPatch TuesdayRCESMA1000SSRFSharePointSonicWallWordPress REST APIactively exploitedcode injectiondeserializationhotfixpatchingremote code executionunauthenticatedvulnerability intelligencewordpresswp2shellzero-day
What happened
Rapid7 blog roundup (mid-July 2026) highlights multiple high-impact vulnerabilities and ecosystem updates. Key security advisories include CVE-2026-63030 (“wp2shell”), an unauthenticated RCE via the WordPress REST API batch endpoint affecting WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1; CVE-2026-58644, a SharePoint deserialization RCE (CVSS 9.8) with confirmed active exploitation and CISA KEV listing; and two actively exploited SonicWall SMA1000 zero-days—CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection/local escalation). The posts also cover Microsoft’s large July Patch Tuesday (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- f8704926a1dd6ebeb0e40177c62f8084b8c35ac37de83b840876d73350134997
- Enrichment time
- 2026-07-19T19:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.