Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2026-63030 [Critical]

Curated 2 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-63030.

Vendor
WordPress
Product
WordPress Core
Affected versions
WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1; fixed in 6.9.5 and 7.0.2
Coverage Span
2026-07-17
Reports
2 related reports

Associated Reports & Timeline

2.
aikido.dev | vulnerability | Critical | | original ↗ | #rce | #featured | #vulnerability-research | #rest-api
WP2Shell chains CVE-2026-63030 in WordPress REST batch routing with the CVE-2026-60137 SQL-injection primitive to achieve pre-authentication remote code execution on stock WordPress installations. Versions 6.9.5 and 7.0.2 contain the fixes.
Why it matters: WP2Shell chains a WordPress core REST routing flaw with SQL injection into pre-authentication RCE on stock installations. Affected sites should move immediately to 6.9.5 or 7.0.2.