WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

Summary

A critical SQL injection vulnerability in WordPress Core, named 'wp2shell' and assigned CVE-2026-63030, has been discovered and is actively being exploited. This vulnerability allows for unauthenticated remote code execution.

IFF Assessment

FOE

The discovery and active exploitation of a critical vulnerability in a widely used platform like WordPress represent a significant threat to defenders.

Severity

9.8 Critical

This SQL injection vulnerability leading to unauthenticated remote code execution in WordPress Core warrants a high CVSS score due to its potential for widespread impact and ease of exploitability.

Defender Context

Defenders should prioritize patching or mitigating this vulnerability in all WordPress installations immediately. The active exploitation indicates a high risk of compromise for unpatched systems, requiring vigilance for signs of intrusion.

Read Full Story →