WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

2026-07-21T01:23:43Z6d6a4bb967d62ebe9efeed936c98451507f37a83e85307cd27cd58425e8fef68
active-exploitationcriticalcve-2026-63030sql-injectionunauthenticated-rceweb-applicationwordpresswp2shell

What happened

A newly publicized WordPress Core SQL injection vulnerability dubbed “wp2shell” has been assigned CVE-2026-63030. The flaw is in WordPress Core (not a plugin) and can lead to unauthenticated remote code execution; proof-of-concept and active exploitation were reported shortly after disclosure. Because WordPress is widely deployed and the issue enables unauthenticated RCE, it represents a high-impact/critical risk and should be mitigated or patched immediately.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
6d6a4bb967d62ebe9efeed936c98451507f37a83e85307cd27cd58425e8fef68
Enrichment time
2026-07-21T01:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) · Baitaphish