Skip to content
Threat Feed
critical threat exploited PoC

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

CVE search metadata

CVE search record: CVE-2026-63030. Severity: critical. CVSS: 9.8. EPSS: 8.95%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-60137. Severity: medium. CVSS: 5.9. EPSS: 4.03%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-15409. Severity: critical. CVSS: 10.0. EPSS: 1.40%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-15410. Severity: high. CVSS: 7.2. EPSS: 1.49%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-56164. Severity: medium. CVSS: 5.3. EPSS: 5.60%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-56155. Severity: high. CVSS: 7.8. EPSS: 0.38%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-14960. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-14961. Severity: medium. CVSS: 6.2. EPSS: 0.12%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-33894. Severity: high. CVSS: 7.5. EPSS: 0.34%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-42533. Severity: high. CVSS: 8.1. EPSS: 0.83%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-60005. Severity: high. CVSS: 8.2. EPSS: 0.61%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-56434. Severity: medium. CVSS: 6.5. EPSS: 0.39%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-20296. Severity: high. CVSS: 8.3. EPSS: 0.17%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-20297. Severity: high. CVSS: 7.2. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

CVE search record: CVE-2026-15265. Severity: critical. CVSS: 9.1. EPSS: 0.36%. KEV: no. Product: WordPress Core 6.9.0, WordPress Core 6.9.1, WordPress Core 6.9.2, WordPress Core 6.9.3, WordPress Core 6.9.4, WordPress Core 7.0.0, WordPress Core 7.0.1, WordPress (6.8.0 – 6.8.5), WordPress (6.9.0 – 6.9.4), WordPress (7.0.0 – 7.0.1), WordPress (< 6.9.5), WordPress (< 7.0.2), WordPress Core, SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, OpenSSL (< 4.0.1), OpenSSL (< 3.6.3), OpenSSL (< 3.5.7), OpenSSL (< 3.4.6), OpenSSL (< 3.0.21), SharePoint Server, Active Directory Federation Services, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, SAP, RabbitMQ, n8n, Monsta FTP, tdeio64.sys driver, node-forge, AI Platform, NGINX Plus, NGINX Open Source, Splunk Enterprise, Tenable Agent, Inspect Connector, Tanium Server, HTTP/2 server implementations, SGLang, 7-Zip, Apache Tomcat, AnyDesk, Kyverno, Trezor Suite, Ledger Wallet, Ledger Live, ComfyUI, Ollama, Open WebUI, Langflow, Gradio, WordPress 6.9.0 - 6.9.4, WordPress 7.0.0 - 7.0.1. Brief: CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core. Brief link: https://feed.craftedsignal.io/briefs/2026-07-wp2shell-rce-wordpress/

What's new

  • 1. new product Jul 20, 21:52 via dark-reading
  • 2. added CVE-2026-14960 +12; OS windows; OS linux Jul 20, 13:56 via the-hacker-news
  • 3. new product Jul 20, 05:22 via securityweek
  • 4. poc_available; added CVE-2026-60137 Jul 19, 15:00 via sploitus

On July 17, 2026, a GitHub Security Advisory was published detailing CVE-2026-63030, a critical unauthenticated remote code execution vulnerability in WordPress Core. This flaw affects WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The vulnerability allows an unauthenticated attacker to execute arbitrary code by exploiting the WordPress REST API batch endpoint, specifically when a persistent object cache is not in use. This could lead to a complete compromise of the website and its underlying data without requiring any valid account or user interaction. While the vulnerability has a CVSS score of 7.5, its unauthenticated nature and widespread deployment of WordPress elevate its criticality. The issue is fixed in WordPress 6.9.5 and 7.0.2. At the time of publication, no publicly confirmed in-the-wild exploitation has been observed, but given WordPress's open-source nature and the potential for AI analysis, public proof-of-concept exploits are highly anticipated.

Attack Chain

  1. Reconnaissance: An attacker identifies public-facing WordPress instances using web scanning tools or open-source intelligence.
  2. Vulnerability Identification: The attacker determines that the target WordPress instance is running a vulnerable version (6.9.0-6.9.4 or 7.0.0-7.0.1) and that a persistent object cache, which could mitigate the exploit, is not in use.
  3. Payload Crafting: The attacker crafts a malicious HTTP POST request, embedding arbitrary code within a specially formatted batch request to the WordPress REST API batch endpoint (e.g., /wp-json/batch/v1).
  4. Initial Access: The crafted request is sent to the vulnerable WordPress server, targeting the REST API batch endpoint.
  5. Code Execution: The WordPress core, due to CVE-2026-63030, improperly processes the batch request, leading to the execution of the attacker's arbitrary code on the server, exploiting the vulnerable code path enabled by the absence of a persistent object cache.
  6. Persistence and Privilege Escalation: The executed code establishes persistence (e.g., dropping a webshell, creating new administrator accounts, modifying WordPress core files) and may attempt to escalate privileges on the underlying host operating system.
  7. Impact: The attacker gains full control over the WordPress instance and potentially the server, enabling actions such as data exfiltration, website defacement, or using the compromised server as a platform for further attacks.

Impact

Successful exploitation of CVE-2026-63030 grants an unauthenticated attacker remote code execution capabilities on the vulnerable WordPress server. This directly leads to the complete compromise of the website, its content, and any associated databases. Given that WordPress is the most widely used content management system globally, a large number of public-facing websites are potentially at risk. The impact extends to potential data breaches, website defacement, server-side resource abuse (e.g., for cryptocurrency mining or hosting malicious content), and further lateral movement within an organization's network if the WordPress server has access to internal systems.

Recommendation

  • Immediately upgrade all affected WordPress installations to version 6.9.5 or 7.0.2 (or 7.1 Beta 2 for the beta branch) to remediate CVE-2026-63030.
  • Verify that automatic updates for WordPress are active and have successfully applied the necessary patches to all internet-facing instances.
  • Review web server access logs for suspicious POST requests to WordPress REST API batch endpoints (e.g., paths containing /wp-json/batch/v1) from unknown or unusual IP addresses, especially around the vulnerability disclosure date.

Indicators of compromise

6

file_path

2

organization

TypeValue
file_path.ssh/authorized_keys
file_path/dev/shm/.a
file_path/var/tmp/.a
file_path/tmp/.a
file_path/etc/cron.d/.sys_monitor
file_path/etc/cron.d/.s
organizationKudankulam Nuclear Power Plant
organizationReliance Infra (RPOWER)