WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Summary
A critical SQL injection vulnerability in WordPress Core, named 'wp2shell' and assigned CVE-2026-63030, has been discovered and is actively being exploited. This vulnerability allows for unauthenticated remote code execution.
IFF Assessment
FOE
The discovery and active exploitation of a critical vulnerability in a widely used platform like WordPress represent a significant threat to defenders.
Severity
9.8
Critical
Defender Context
Defenders should prioritize patching or mitigating this vulnerability in all WordPress installations immediately. The active exploitation indicates a high risk of compromise for unpatched systems, requiring vigilance for signs of intrusion.