VULNERABILITY OVERVIEW
A REST API batch-route confusion flaw (CVE-2026-63030) chains with a SQL injection in WP_Query (CVE-2026-60137) to deliver unauthenticated pre-authentication remote code execution on default WordPress installations with no plugins or special configuration required. A working PoC appeared within hours of the July 17 disclosure; VulnCheck verified 24+ unique PoCs by July 19 and in-the-wild exploitation was confirmed by July 18–20. CISA added both CVEs to KEV on July 21, 2026; Coalition honeypots captured active exploitation attempts in the wild.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 (full RCE chain); 6.8.0–6.8.5 (SQLi only)CITATIONS
- → https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core/
- → https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog
- → https://www.vulncheck.com/blog/wp2shell
- → https://www.tenable.com/blog/wp2shell-cve-2026-63030-cve-2026-60137-frequently-asked-questions-about-remote-code-execution
- → https://socradar.io/blog/wp2shell-wordpress-rce-cve-2026-63030/