Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4187 articles · 222128 vulns · 36/41 feeds (7d)
← Back to list
9.8
CVE-2026-63030KEVEXPLOITEDPATCHED
wordpress · wordpress

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Affected Products

VendorProductVersions
wordpresswordpress6.9.0, 7.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcewordpresscert_advisory90%

References

  • https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q(vdb-entry, technical-description)
  • https://wordpress.org/news/2026/07/wordpress-7-0-2-release/(release-notes, vendor-advisory)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-63030.yaml(exploit, nuclei)

Related News (23 articles)

Tier C
Rapid7 Blog27d ago
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
→ No new info (linked only)
Tier B
CERT-FR45d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier B
CERT-FR59d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier C
Cisco Talos62d ago
Don’t swing at everything
→ No new info (linked only)
Tier E
Reddit r/cybersecurity64d ago
WP2Shell: Hands-On Lab Reproducing the Pre-Auth WordPress Core RCE
→ No new info (linked only)
Tier D
BleepingComputer64d ago
Critical wp2shell WordPress flaws exploited to install webshells
→ No new info (linked only)
Tier D
Heise Security65d ago
WordPress-Lücke „wp2shell“ wird angegriffen
→ No new info (linked only)
Tier D
The Hacker News65d ago
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
→ No new info (linked only)
Tier D
Dark Reading65d ago
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
→ No new info (linked only)
Tier B
CCCS Canada65d ago
WordPress security advisory (AV26-723)
→ No new info (linked only)
Tier D
Infosecurity Magazine66d ago
Researchers Build WordPress Exploit Using OpenAI's GPT
→ No new info (linked only)
Tier B
BSI Advisories66d ago
[NEU] [kritisch] WordPress: Mehrere Schwachstellen ermöglichen Codeausführung
→ No new info (linked only)
Tier E
Reddit r/cybersecurity66d ago
WP2Shell WordPress Vulnerabilities Exploited in the Wild
→ No new info (linked only)
Tier D
SecurityWeek66d ago
WP2Shell WordPress Vulnerabilities Exploited in the Wild
→ No new info (linked only)
Tier B
CERT-FR66d ago
Multiples vulnérabilités dans WordPress (20 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR66d ago
Multiples vulnérabilités dans WordPress (20 juillet 2026)
→ No new info (linked only)
Tier E
Hacker News67d ago
Wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core
→ No new info (linked only)
Tier E
Reddit r/netsec67d ago
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner
→ No new info (linked only)
Tier D
BleepingComputer67d ago
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
→ No new info (linked only)
Tier E
Reddit r/cybersecurity68d ago
Technical analysis of wp2shell: The latest WordPress Core pre-auth RCE chain
→ No new info (linked only)
Tier D
Heise Security68d ago
„wp2shell“: Kritische WordPress-Lücke erlaubt Codeeinschleusung über API
→ No new info (linked only)
Tier C
Rapid7 Blog68d ago
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
→ No new info (linked only)
Tier C
VulDB68d ago
CVE-2026-63030 | WordPress up to 6.9.4/7.0.1 REST API Batch Endpoint interpretation conflict
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
6.9.57.0.2
PublishedJul 17, 2026
Last enriched66d agov12
Tags
unauthenticateddefault-installationobject-cache-bypasswp2shellbatch-endpointrest-api-bypasspre-authenticationpublic-exploitpublic-exploit-releasedforced-auto-updatewaf-mitigation-availablecve-2026-63030exploited-in-the-wildhexastrike-observedpatchstack-confirmedwatchtowr-observedcloudflare-mitigationai-assisted-discoverycert-fr-confirmedai-assisted-exploit-developmentmulti-stage-exploit-chaincache-poisoningcustomize-changeset-abuseoEmbed-cache-manipulationgpt5.6-sol-ultrasearchlight-cyberai-exploit-generationmulti-stage-exploit-chain-confirmedpre-auth-rce-confirmeddefault-install-confirmedno-preconditionsstock-wordpresszero-day-broker-interest
Trending Score4
Source articles23
Independent15
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-87902EXPKEV
CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph
Trending: 135
MEDIUMCVE-2026-60137EXPKEV
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
Trending: 3
HIGHCVE-2026-65640
CVE-2026-65640: WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level
Trending: 1
NONECVE-2026-64638
CVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
Trending: 1
CRITICALCVE-2026-6382EXP
Multiple elFinder Plugins - Authenticated OS Command Injection

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Added to CISA KEV
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: severity, cvssEstimate, affectedVersions
Jul 17, 2026
Updated: severity, affectedVersions, tags
Jul 17, 2026
Updated: affectedVersions, cweIds, tags
Jul 18, 2026
Updated: cweIds
Jul 18, 2026
Updated: affectedVersions, tags
Jul 18, 2026
Updated: cweIds, mitreAttack, tags
Jul 18, 2026
Updated: tags
Jul 20, 2026
Updated: affectedVersions
Jul 20, 2026
Updated: affectedVersions, tags
Jul 20, 2026
Updated: tags
Jul 20, 2026
Updated: tags
Jul 20, 2026
Actively Exploited
Jul 22, 2026
Exploit Available
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v12
Last enriched 66d ago
v12Tier D66d ago

Added affected version 6.8.6 (previously missing) and supplemented tags with specific AI model details (GPT5.6 Sol Ultra), discoverer information (Searchlight Cyber), and confirmation of multi-stage exploit chain methodology used in WP2Shell

tags
via Infosecurity Magazine
v11Tier D66d ago

Added significant technical details about the exploit chain mechanics including cache poisoning, customize changeset manipulation, and authentication bypass techniques, plus new tags related to AI-assisted exploit development and multi-stage exploitation.

tags
via Infosecurity Magazine
v10Tier B66d ago

Added WordPress 7.1.0-beta2 as affected version and added CERT-FR confirmation tag

affectedVersionstags
via CERT-FR
v9Tier B66d ago

Added newly affected versions 6.8.6 and 7.1.0 (7.1 beta2) to the affected versions list based on CERT-FR advisory.

affectedVersions
via CERT-FR
v8Tier D66d ago

Clarified affected versions to exclude 6.8.x series (not mentioned in article), added CVE-2026-63030 identifier, and added tags documenting confirmed in-the-wild exploitation by multiple security firms and availability of Cloudflare mitigation rules.

tags
via SecurityWeek
v7Tier D67d ago

Added CWE-942 (route confusion), MITRE ATT&CK techniques T1190 and T1059.001, and new tags reflecting public exploit release and forced auto-update status.

cweIdsmitreAttacktags
via BleepingComputer
v6Tier D67d ago

Updated affected versions list to be more precise (6.9.0-6.9.4 and 7.0.0-7.0.1), added MITRE ATT&CK technique T1190, and added 'pre-authentication' and 'public-exploit' tags reflecting public PoC release.

affectedVersionstags
via BleepingComputer
v5Tier E68d ago

Article identifies CVE-2026-63030 as the primary batch endpoint vulnerability (distinct from CVE-2026-60137 SQL injection), and indicates CWE-78 (OS Command Injection) is relevant to the RCE chain mechanism.

cweIds
via Reddit r/cybersecurity
v4Tier D68d ago

Added affected versions 6.8.x, identified CWE-89 (SQL Injection), and added wp2shell tag and batch-endpoint context. Article clarifies that versions before 6.8 are unaffected, implying 6.8.0-6.8.5 are vulnerable.

affectedVersionscweIdstags
via Heise Security
v3Tier C68d ago

Updated severity from HIGH to CRITICAL per GitHub Security Advisory; expanded affected versions to include 6.9.1-6.9.4 and 7.0.1; added tags indicating unauthenticated attack path and object cache bypass requirement.

severityaffectedVersionstags
via Rapid7 Blog
v2Tier C68d ago

Updated severity to CRITICAL, added CVSS estimate of 9.0, and expanded affected versions to include 6.9.4 and 7.0.1.

severitycvssEstimateaffectedVersions
via VulDB
v168d ago

Initial creation