WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

Summary

A critical SQL injection vulnerability in WordPress Core, named 'wp2shell' and assigned CVE-2026-63030, has been discovered and is actively being exploited. This vulnerability allows for unauthenticated remote code execution.

IFF Assessment

FOE

The discovery and active exploitation of a critical vulnerability in a widely used platform like WordPress represent a significant threat to defenders.

Severity

9.8 Critical

Defender Context

Defenders should prioritize patching or mitigating this vulnerability in all WordPress installations immediately. The active exploitation indicates a high risk of compromise for unpatched systems, requiring vigilance for signs of intrusion.

Read Full Story →