CVE detail
CVE-2026-63030
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 18.0
Why it matters now
Mention timeline
- Total mentions
- 28
- within the 30d window
- Peak daily
- 9
- highest bucket
Evidence
Source links by recency
28 source links · newest first
ading a plugin. The chain consists of two vulnerabilities: an unauthenticated SQL injection vulnerability identified as CVE-2026-60137 , and a REST API batch request route confusion vulnerability identified as CVE-2026-63030 , which can be chained with the SQL injection to escalate the impact to unauthenticated administrator account creation. The prima
vendorwww.wordfence.comJul 29, 2026, 4:04 PM- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)Wordfence
re 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-63030 Patch Status Patched Published Jul 17, 2026 Affected Software WordPress [wordpress] Researcher Adam Kues More Details > Digits: WordPress Mobile Number Signup and Login Loco Translate Paid Membership Plugin, Ecommerce,
vendorwww.wordfence.comJul 23, 2026, 8:42 PM - Don’t swing at everythingCisco Talos
llions of WordPress sites to remote takeover Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. ( DarkReading ) Progress tells ShareFile customers to shut down Storage Zone Controllers over security threat Only t
vendorblog.talosintelligence.comJul 23, 2026, 6:00 PM - U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
nd WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog . Below are the flaws added to the KeV catalog: CVE-2021-27137 (CVSS score of 8.1) DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 (CVSS score of 9.8) Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 (CVSS score of 9.8) W
newssecurityaffairs.comJul 22, 2026, 10:45 AM t’s config is now the payload: How attackers are targeting the… By Tom Abai Cyber Exposure Alerts Jul 20 2026 wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about… By Satnam Narang Exposure Management Vulnerability Management Tenable Lumin Tenable Nessus Tenable Nessus Network Monitor Tenable One Tenable Patch Management Tenable
vendorwww.tenable.comJul 21, 2026, 9:07 PM- Critical wp2shell WordPress flaws exploited to install webshellsBleepingComputer
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]
newswww.bleepingcomputer.comJul 21, 2026, 4:41 PM ur new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability CVE-2026
governmentwww.cisa.govJul 21, 2026, 12:00 PMnticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well
newsthehackernews.comJul 21, 2026, 8:59 AMCVE-2026-60137 and CVE-2026-63030 can be chained to enable unauthenticated remote code execution against vulnerable WordPress Core installations. Learn how to validate exposure and verify remediation.
exploithorizon3.aiJul 20, 2026, 10:32 PM- Attackers pummel critical WordPress vuln to create all sorts of mischiefThe Register Security
ns,” Jake Knott, watchTowr principal security researcher, told The Register. “WatchTowr was able to trivially reproduce CVE-2026-63030 within minutes of disclosure, and the second CVE-2026-60137 with some additional effort.” WordPress released patches for both CVEs late Friday, but by Saturday it was game over. “By the early hours of Saturday morning,
newswww.theregister.comJul 20, 2026, 9:57 PM - wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a DecadeWordfence
delay. Key takeaways: wp2shell is a critical, unauthenticated remote code execution chain in WordPress Core, tracked as CVE-2026-60137 and CVE-2026-63030 . Exploitation does not require a vulnerable plugin, a vulnerable theme, or authenticated access. WordPress released patched versions 6.8.6 , 6.9.5 , and 7.0.2 on July 17, 2026. WordPress 6.9.x and 7.
vendorwww.wordfence.comJul 20, 2026, 9:49 PM Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
newswww.darkreading.comJul 20, 2026, 9:38 PM- Researchers Build WordPress Exploit Using OpenAI's GPTInfosecurity Magazine
fully develop a full exploit chain for two critical WordPress Core vulnerabilities. The first vulnerability, tracked as CVE-2026-63030 is a critical REST API batch endpoint route confusion issue (CVSS rating: 9.8) affecting WordPress Core versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2. The second, CVE-2026-60137, is a high-severity author__not_in W
newswww.infosecurity-magazine.comJul 20, 2026, 2:00 PM An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of
vendorwww.tenable.comJul 20, 2026, 1:36 PM- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThe Hacker News
on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) explo
newsthehackernews.comJul 20, 2026, 1:32 PM - 20th July – Threat Intelligence ReportCheck Point Research
day, the largest monthly release recorded by the company. Two vulnerabilities were under active exploitation, including CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both vulnerabilities could allow attackers to elevate privileges. Check Point IPS provides protection against these threats (Microsoft Sha
vendorresearch.checkpoint.comJul 20, 2026, 12:18 PM Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .
newswww.securityweek.comJul 20, 2026, 5:21 AMpt exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations […]
newssecurityaffairs.comJul 19, 2026, 5:04 AMLinked URL: https://fullhunt.io/blog/2026/07/17/wp2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html | Posted by mazen160 | 3 points | 0 comments
communitynews.ycombinator.comJul 18, 2026, 9:23 PM- Two new high severity WordPress vulnerabilities, patch immediately!Help Net Security
one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-63030 – A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetn
newswww.helpnetsecurity.comJul 18, 2026, 2:57 PM core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase its impact to unauthenticated remote code execution and is identified as CVE-2026-63030. To protect WordPress ... Read More The post PSA: WordPress Cor
vendorwww.wordfence.comJul 17, 2026, 11:03 PMOverview On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030 , a critical unauthenticated remote code execution vulnerability affecting WordPress Core . While the official GitHub security advisory classifies the severity as Critical, the vulnerability has currently been assigned
vendorwww.rapid7.comJul 17, 2026, 10:23 PMwhat it calls forced updates through its auto-update system. wp2shell is two bugs, not one, and both now carry CVE IDs. CVE-2026-63030 is the REST API batch-route confusion; CVE-2026-60137 is a SQL injection in WordPress core. Chained, they take an anonymous request all the way to code execution. Since Friday, the full mechanism has been published, and
newsthehackernews.comJul 17, 2026, 9:20 PMNo excerpt available.
Mitigationwww.cisa.govJul 17, 2026, 8:17 PMNo excerpt available.
Release Noteswordpress.orgJul 17, 2026, 8:17 PMNo excerpt available.
Exploitgithub.comJul 17, 2026, 8:17 PMt’s config is now the payload: How attackers are targeting the… By Tom Abai Cyber Exposure Alerts Jul 20 2026 wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about… By Satnam Narang Exposure Management Your exposure ends here Your exposure ends here Your exposure ends here Your exposure ends here Your exposure ends here Your expos
vendorwww.tenable.comJul 16, 2026, 1:00 PMt’s config is now the payload: How attackers are targeting the… By Tom Abai Cyber Exposure Alerts Jul 20 2026 wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about… By Satnam Narang Exposure Management Tenable One Your exposure ends here Your exposure ends here Your exposure ends here Your exposure ends here Your exposure ends her
vendorwww.tenable.comJul 15, 2026, 12:45 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
14 repository references · best confidence 0.99 · max 351 stars
- sowarma/wp2shell-PoCHigh confidencegithubRepository topic discovery351 starsDiscovered Aug 5, 2026, 6:51 PM
- securelayer7/WordPresShellHigh confidencegithubRepository topic discovery9 starsDiscovered Jul 18, 2026, 8:51 PM
- Lutfifakee-Project/wp2shellHigh confidencegithubRepository topic discovery6 starsDiscovered Jul 18, 2026, 6:51 AM
- GhostInExile/CVE-2026-63030-Wp2ShellHigh confidencegithubRepository topic discovery4 starsDiscovered Jul 21, 2026, 4:51 AM
- M4xSec/wp2shell-Exploit-Waf-BypassMedium confidencegithubRepository topic discovery3 starsDiscovered Aug 8, 2026, 6:51 PM
- HackingLZ/wp2shell_stock_chainHigh confidencegithubRepository topic discovery3 starsDiscovered Jul 18, 2026, 8:51 PM
- ebrasha/abdal-cve-2026-63030High confidencegithubRepository topic discovery2 starsDiscovered Jul 18, 2026, 8:51 PM
- gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-pocHigh confidencegithubRepository topic discovery1 starsDiscovered Jul 22, 2026, 4:51 PM
- Ch4120N/CVE-2026-63030High confidencegithubRepository topic discovery1 starsDiscovered Jul 20, 2026, 6:51 PM
- 0xjessie21/wp2shell-checkerHigh confidencegithubRepository topic discovery1 starsDiscovered Jul 20, 2026, 8:51 AM
- shinthink/CVE-2026-63030High confidencegithubRepository topic discovery0 starsDiscovered Jul 24, 2026, 10:51 AM
- mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpressHigh confidencegithubRepository topic discovery0 starsDiscovered Jul 21, 2026, 6:51 PM
- Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2ShellMedium confidencegithubRepository topic discovery0 starsDiscovered Jul 30, 2026, 10:51 PM
- Bhanunamikaze/WP2Shell-CVE-2026-63030-POCHigh confidencegithubRepository topic discovery0 starsDiscovered Jul 21, 2026, 6:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-18427CVSS 7.5 · High
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not…
- CVE-2026-69246CVSS 7.2 · High
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set…
- CVE-2026-18446CVSS 7.5 · High
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it…
- CVE-2026-14643CVSS 5.9 · Medium
undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to befo…
- CVE-2026-67201CVSS 7.7 · High
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploitin…
- CVE-2026-49332CVSS 8.5 · High
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys…