Skip to main content

CVE detail

CVE-2026-63030

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

CVSS 9.8 · CriticalBuzz score 93.0KEV listed14 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 93.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 18.0
Mention score
30.0
28 evidence mentions in the snapshot
Diversity score
20.0
19 sources across 8 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
18.0
14 repos · best confidence 0.99
Best PoC traction
351
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
28
within the 30d window
Peak daily
9
highest bucket

Evidence

Source links by recency

Newest mentions first
28 source links · newest first
  • ading a plugin. The chain consists of two vulnerabilities: an unauthenticated SQL injection vulnerability identified as CVE-2026-60137 , and a REST API batch request route confusion vulnerability identified as CVE-2026-63030 , which can be chained with the SQL injection to escalate the impact to unauthenticated administrator account creation. The prima

    vendorwww.wordfence.comJul 29, 2026, 4:04 PM
  • re 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-63030 Patch Status Patched Published Jul 17, 2026 Affected Software WordPress [wordpress] Researcher Adam Kues More Details > Digits: WordPress Mobile Number Signup and Login Loco Translate Paid Membership Plugin, Ecommerce,

    vendorwww.wordfence.comJul 23, 2026, 8:42 PM
  • Don’t swing at everythingCisco Talos

    llions of WordPress sites to remote takeover Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. ( DarkReading ) Progress tells ShareFile customers to shut down Storage Zone Controllers over security threat Only t

    vendorblog.talosintelligence.comJul 23, 2026, 6:00 PM
  • nd WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog . Below are the flaws added to the KeV catalog: CVE-2021-27137 (CVSS score of 8.1) DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 (CVSS score of 9.8) Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 (CVSS score of 9.8) W

    newssecurityaffairs.comJul 22, 2026, 10:45 AM
  • t’s config is now the payload: How attackers are targeting the… By Tom Abai Cyber Exposure Alerts Jul 20 2026 wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about… By Satnam Narang Exposure Management Vulnerability Management Tenable Lumin Tenable Nessus Tenable Nessus Network Monitor Tenable One Tenable Patch Management Tenable

    vendorwww.tenable.comJul 21, 2026, 9:07 PM
  • Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]

    newswww.bleepingcomputer.comJul 21, 2026, 4:41 PM
  • ur new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability CVE-2026

    governmentwww.cisa.govJul 21, 2026, 12:00 PM
  • nticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well

    newsthehackernews.comJul 21, 2026, 8:59 AM
  • CVE-2026-60137 and CVE-2026-63030 can be chained to enable unauthenticated remote code execution against vulnerable WordPress Core installations. Learn how to validate exposure and verify remediation.

    exploithorizon3.aiJul 20, 2026, 10:32 PM
  • ns,” Jake Knott, watchTowr principal security researcher, told The Register. “WatchTowr was able to trivially reproduce CVE-2026-63030 within minutes of disclosure, and the second CVE-2026-60137 with some additional effort.” WordPress released patches for both CVEs late Friday, but by Saturday it was game over. “By the early hours of Saturday morning,

    newswww.theregister.comJul 20, 2026, 9:57 PM
  • delay. Key takeaways: wp2shell is a critical, unauthenticated remote code execution chain in WordPress Core, tracked as CVE-2026-60137 and CVE-2026-63030 . Exploitation does not require a vulnerable plugin, a vulnerable theme, or authenticated access. WordPress released patched versions 6.8.6 , 6.9.5 , and 7.0.2 on July 17, 2026. WordPress 6.9.x and 7.

    vendorwww.wordfence.comJul 20, 2026, 9:49 PM
  • Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

    newswww.darkreading.comJul 20, 2026, 9:38 PM
  • Researchers Build WordPress Exploit Using OpenAI's GPTInfosecurity Magazine

    fully develop a full exploit chain for two critical WordPress Core vulnerabilities. The first vulnerability, tracked as CVE-2026-63030 is a critical REST API batch endpoint route confusion issue (CVSS rating: 9.8) affecting WordPress Core versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2. The second, CVE-2026-60137, is a high-severity author__not_in W

    newswww.infosecurity-magazine.comJul 20, 2026, 2:00 PM
  • An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of

    vendorwww.tenable.comJul 20, 2026, 1:36 PM
  • on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) explo

    newsthehackernews.comJul 20, 2026, 1:32 PM
  • 20th July – Threat Intelligence ReportCheck Point Research

    day, the largest monthly release recorded by the company. Two vulnerabilities were under active exploitation, including CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both vulnerabilities could allow attackers to elevate privileges. Check Point IPS provides protection against these threats (Microsoft Sha

    vendorresearch.checkpoint.comJul 20, 2026, 12:18 PM
  • Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .

    newswww.securityweek.comJul 20, 2026, 5:21 AM
  • pt exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations […]

    newssecurityaffairs.comJul 19, 2026, 5:04 AM
  • Linked URL: https://fullhunt.io/blog/2026/07/17/wp2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html | Posted by mazen160 | 3 points | 0 comments

    communitynews.ycombinator.comJul 18, 2026, 9:23 PM
  • one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-63030 – A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetn

    newswww.helpnetsecurity.comJul 18, 2026, 2:57 PM
  • core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase its impact to unauthenticated remote code execution and is identified as CVE-2026-63030. To protect WordPress ... Read More The post PSA: WordPress Cor

    vendorwww.wordfence.comJul 17, 2026, 11:03 PM
  • Overview On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030 , a critical unauthenticated remote code execution vulnerability affecting WordPress Core . While the official GitHub security advisory classifies the severity as Critical, the vulnerability has currently been assigned

    vendorwww.rapid7.comJul 17, 2026, 10:23 PM
  • what it calls forced updates through its auto-update system. wp2shell is two bugs, not one, and both now carry CVE IDs. CVE-2026-63030 is the REST API batch-route confusion; CVE-2026-60137 is a SQL injection in WordPress core. Chained, they take an anonymous request all the way to code execution. Since Friday, the full mechanism has been published, and

    newsthehackernews.comJul 17, 2026, 9:20 PM
  • No excerpt available.

    Mitigationwww.cisa.govJul 17, 2026, 8:17 PM
  • No excerpt available.

    Release Noteswordpress.orgJul 17, 2026, 8:17 PM
  • No excerpt available.

    Exploitgithub.comJul 17, 2026, 8:17 PM
  • t’s config is now the payload: How attackers are targeting the… By Tom Abai Cyber Exposure Alerts Jul 20 2026 wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about… By Satnam Narang Exposure Management Your exposure ends here Your exposure ends here Your exposure ends here Your exposure ends here Your exposure ends here Your expos

    vendorwww.tenable.comJul 16, 2026, 1:00 PM
  • t’s config is now the payload: How attackers are targeting the… By Tom Abai Cyber Exposure Alerts Jul 20 2026 wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about… By Satnam Narang Exposure Management Tenable One Your exposure ends here Your exposure ends here Your exposure ends here Your exposure ends here Your exposure ends her

    vendorwww.tenable.comJul 15, 2026, 12:45 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

14 repository references · best confidence 0.99 · max 351 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-18427

    @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not…

    CVSS 7.5 · High
    2 mentions
  • CVE-2026-69246

    Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set…

    CVSS 7.2 · High
  • CVE-2026-18446

    fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it…

    CVSS 7.5 · High
    2 mentions
  • CVE-2026-14643

    undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to befo…

    CVSS 5.9 · Medium
    2 mentions
  • CVE-2026-67201

    V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploitin…

    CVSS 7.7 · High
    4 mentions
  • CVE-2026-49332

    A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys…

    CVSS 8.5 · High
    2 mentions