CVE-2026-63030
published 2026-07-17CVE-2026-63030: WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-24
Exploited in the wild
EPSS
98.05%
99.9th percentile
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wordpress | wordpress | < 7.0.2 | 7.0.2 |
| wordpress | wordpress | >= 6.9 < 6.9.5 | 6.9.5 |
| wordpress | wordpress | >= 7.0 < 7.0.2 | 7.0.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated requests to the WordPress REST API batch endpoint (e.g., /wp-json/batch/v1) that include query parameters consistent with WP_Query author__not_in manipulation, which is the chained SQL injection vector (CVE-2026-60137). ↗
- →The vulnerable code path can be reached when a persistent object cache is NOT in use on the WordPress installation — prioritize detection and patching on sites without persistent object caching. ↗
- →No authentication, plugins, or user interaction are required to exploit this vulnerability — treat any anomalous unauthenticated REST API batch requests as high-priority alerts. ↗
- →Affected WordPress versions are 6.9.0–6.9.4 and 7.0.0–7.0.1; fingerprint version strings in HTTP responses or /wp-includes/version.php to identify unpatched instances. ↗
- →CVE-2026-63030 is chained with CVE-2026-60137 (author__not_in WP_Query SQL Injection / GHSA-fpp7-x2x2-2mjf); detection rules should account for both the route confusion trigger and the SQL injection payload in the same request flow. ↗
- ·The exploit chain only works when a persistent object cache is absent. WordPress sites with a persistent object cache (e.g., Redis, Memcached) are not reachable via this vulnerable code path, which should be factored into risk prioritization. ↗
- ·WordPress versions prior to 6.8 are not affected by either CVE-2026-63030 or CVE-2026-60137; WordPress 6.8.x is only affected by CVE-2026-60137 (the SQL injection component), not the RCE chain. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.1CRITICAL
cisa5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
WordPress Core SQL Injection Vulnerability
cisa·2026-07-21·CVSS 5.9
CVE-2026-60137 [MEDIUM] CWE-89 WordPress Core SQL Injection Vulnerability
Vulnerability: WordPress Core SQL Injection Vulnerability
Affected: WordPress Core
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet
CISA
WordPress Core Interpretation Conflict Vulnerability
cisa·2026-07-21·CVSS 5.9
CVE-2026-63030 [MEDIUM] CWE-436 WordPress Core Interpretation Conflict Vulnerability
Vulnerability: WordPress Core Interpretation Conflict Vulnerability
Affected: WordPress Core
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching gu
WordPress
WordPress 7.0.2 Release
vendor_wordpress·2026-07-17·CVSS 9.1
CVE-2026-63030 [CRITICAL] WordPress 7.0.2 Release
Title: WordPress 7.0.2 Release
WordPress 7.0.2 is now available.
The 7.0.2 security release addresses one critical and one high severity security issue.
Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions.
To manually update you can visit your WordPress Dashboard, click “Updates”, and then click “Update Now”, or you can download WordPress 7.0.2 from WordPress.org . On sites that support automatic background updates, the update process will begin automatically.
Security updates included in this release
The security team would like to thank the following people for responsibly reporting vulnerabilities and allow
VulDB
WordPress up to 6.9.4/7.0.1 REST API Batch Endpoint interpretation conflict (EUVD-2026-45280)
vuldb·2026-07-17·CVSS 7.5
CVE-2026-63030 [HIGH] WordPress up to 6.9.4/7.0.1 REST API Batch Endpoint interpretation conflict (EUVD-2026-45280)
A vulnerability categorized as critical has been discovered in WordPress up to 6.9.4/7.0.1. This affects an unknown function of the component REST API Batch Endpoint. The manipulation results in interpretation conflict.
This vulnerability is identified as CVE-2026-63030. The attack can be executed remotely. There is not any exploit available.
VulnCheck
Interpretation Conflict
vulncheck·2026·CVSS 9.1
CVE-2026-63030 [CRITICAL] Interpretation Conflict
Interpretation Conflict
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://patchstack.com/database/wordpress/plugin/wordpress/vulnerability/wordpress-core-7-0-1-unauthenticated-remote-code-execution-vulnerability
No detection rules found.
Nuclei
WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
nuclei·CVSS 5.9
CVE-2026-63030 [MEDIUM] WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
WordPress core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are vulnerable to a pre-authentication timing-based blind SQL injection via the REST API batch endpoint. A route confusion vulnerability (CVE-2026-63030) allows nested batch requests to bypass authentication checks, while a SQL injection flaw (CVE-2026-60137) in the author_exclude parameter of /wp/v2/categories allows arbitrary SQL queries via a SLEEP-based timing oracle. An unauthenticated attacker can extract the full database contents including user credentials.
Template:
id: CVE-2026-63030
info:
name: WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
author: slcyber,mielverkerken,pdteam
severity: critical
d
Talos
Don’t swing at everything
blogs_talos·2026-07-23
CVE-2026-60137 Don’t swing at everything
## Don’t swing at everything
Welcome to this week’s edition of the Threat Source newsletter.
Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance , and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn't limited to closed models anymore.
On the other side of that line, real-world impact hasn't caught up yet and we're living in an artificial buffer zone. For me, defining the “pre-” and “po
Hackernews
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
blogs_hackernews·2026-07-22·CVSS 7.5
CVE-2026-29059 [HIGH] Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.
The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}").
"The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences," according to an advisory published b
Tenable
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
blogs_tenable·2026-07-21
CVE-2026-63030 Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
## Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' own tools.
## Key takeaways
AI coding assistant configuration files, such as settings.json hooks, .cursorrules Cursor MDC rules, and similar harness files, are now explicit targets in supply-chain attacks, not collateral damage.
These files simultaneously sit at the intersection of three trust relationships: The developer trusts them as config, the integrated development environment (IDE) executes them automatic
Tenable
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
blogs_tenable·2026-07-21
CVE-2026-63030 Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
## Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.
## Key Takeaways
The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.
261 issues (18% of all patches) were assigned a critical severity rating
Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches
## Background
On July 21, Oracle released its Critical Patch Update (CPU) for July 2026 , the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this q
Hackernews
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
blogs_hackernews·2026-07-21·CVSS 5.9
CVE-2026-63030 [MEDIUM] WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137 , have been codenamed wp2shell .
"By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public," Ja
Wiz
Exploitation in the Wild of wp2shell
blogs_wiz·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] Exploitation in the Wild of wp2shell
## What are CVE-2026-63030 & CVE-2026-60137?
These vulnerabilities comprise a critical pre-authentication remote code execution (RCE) chain in WordPress Core, dubbed "wp2shell", discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol, and published on July 17th, 2026. This exploit chain allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
## What’s the risk to cloud environments?
Our data indicates that 60% of organizations using WordPress initially had at least one vulnerable instance at the time these CVEs were published, and 25% were exposing a vulnerable server to the Internet. However, this figure is rapidly declining as organizations patch, lowering to 50% and 10% respectively with
Checkpoint
20th July – Threat Intelligence Report
blogs_checkpoint·2026-07-20
CVE-2026-56164 20th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance.
Jscrambler,
Sans Isc
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
blogs_sans_isc·2026-07-20·CVSS 9.8
CVE-2026-63030 [CRITICAL] WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
WordPress Exploitation Underway (CVE-2026-63030)
Published: 2026-07-20. Last Updated: 2026-07-20 18:41:24 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.
If you are running WordPress, stop reading now. Check if you are vulnerable at https://wp2shell.com . Assume compromise if you are vulnerable.
Tenable
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
blogs_tenable·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
## wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.
## Key takeaways:
Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations.
Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing w
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
Rapid7
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
blogs_rapid7·2026-07-17·CVSS 7.5
CVE-2026-63030 [HIGH] CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
## Overview
On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030 , a critical unauthenticated remote code execution vulnerability affecting WordPress Core . While the official GitHub security advisory classifies the severity as Critical, the vulnerability has currently been assigned a CVSS score of 7.5. WordPress is one of the most widely deployed content management systems, making vulnerabilities in its core software potentially significant for organizations operating public-facing websites. The vulnerability reportedly allows an unauthenticated attacker to execute code via the WordPress REST API batch endpoint, potentially resulting in complete compromise of the website and its underlying data. No valid account or user interaction is required.
According to the
2026-07-17
Published
2026-07-21
Added to CISA KEV
Exploited in the wild