WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Summary
A critical SQL injection vulnerability in WordPress Core, named 'wp2shell' and assigned CVE-2026-63030, has been discovered and is actively being exploited. This vulnerability allows for unauthenticated remote code execution.
IFF Assessment
The discovery and active exploitation of a critical vulnerability in a widely used platform like WordPress represent a significant threat to defenders.
Severity
This SQL injection vulnerability leading to unauthenticated remote code execution in WordPress Core warrants a high CVSS score due to its potential for widespread impact and ease of exploitability.
Defender Context
Defenders should prioritize patching or mitigating this vulnerability in all WordPress installations immediately. The active exploitation indicates a high risk of compromise for unpatched systems, requiring vigilance for signs of intrusion.