DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 04:57:08ZSOURCES: 14CRITICAL: 43
⚠ ACTIVE ALERTS
@TalosSecurity CRITICAL — Cl0p (aka Graceful Spider/Lace Tempest) affiliate campaign against PTC Windchill/FlexPLM… /// @MandiantThreats CRITICAL — Active Cl0p double-extortion campaign exploiting CVE-2026-12569 (PTC Windchill/FlexPLM… /// @GossiTheDog CRITICAL — SonicWall SMA1000 situation is worse than the July 14 advisory suggested. Volexity traced… /// @MsftSecIntel CRITICAL — THREAT UPDATE: CVE-2026-6875 (ServiceNow AI Platform pre-auth sandbox-escape RCE, CVSS… /// @MalwareHunterTeam CRITICAL — Fastjson CVE-2026-16723 (CVSS 9.0) — active exploitation confirmed by ThreatBook and…
43Critical Threats
19Active CVEs
11IOCs Tracked
12New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-63030PUBLISHED: 2026-07-17
CRITICALCVE-2026-63030★ CISA KEV LISTED

WordPress wp2shell Pre-Auth RCE Chain

VENDOR: WordPress (Automattic)//PRODUCT: WordPress Core
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

A REST API batch-route confusion flaw (CVE-2026-63030) chains with a SQL injection in WP_Query (CVE-2026-60137) to deliver unauthenticated pre-authentication remote code execution on default WordPress installations with no plugins or special configuration required. A working PoC appeared within hours of the July 17 disclosure; VulnCheck verified 24+ unique PoCs by July 19 and in-the-wild exploitation was confirmed by July 18–20. CISA added both CVEs to KEV on July 21, 2026; Coalition honeypots captured active exploitation attempts in the wild.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSWordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 (full RCE chain); 6.8.0–6.8.5 (SQLi only)
  • https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core/
  • https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog
  • https://www.vulncheck.com/blog/wp2shell
  • https://www.tenable.com/blog/wp2shell-cve-2026-63030-cve-2026-60137-frequently-asked-questions-about-remote-code-execution
  • https://socradar.io/blog/wp2shell-wordpress-rce-cve-2026-63030/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn