ON July 17, 2026, a critical remote code execution vulnerability (CVE-2026-63030) was disclosed in WordPress Core, allowing unauthenticated attackers to exploit a weakness via the REST API. The vulnerability affects WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1, with fixes available in versions 6.9.5 and 7.0.2. Organizations are urged to upgrade immediately to mitigate risks. The vulnerability's potential for widespread impact is heightened by WordPress's popularity as a content management system. Currently, no public exploits have been confirmed in active use, but the risk remains significant due to the nature of the flaw.
WordPress REST API flaw lets attackers run code remotely
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
WordPress wp2shell flaw lets attackers run code before login
elastic.co
-
WordPress wp2shell exploit fuels surge in site scans and attacks
thehackernews.com
-
Critical WordPress Bug Lets Attackers Run Code Remotely
securityonline.info
-
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
darkreading.com
-
WordPress core flaw CVE-2026-63030 lets attackers execute code
isc.sans.edu
-
AI crafted WordPress exploit chain triggers urgent CVE patches
infosecurity-magazine.com
-
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE
securityweek.com
-
Public PoC exploits hit critical WordPress CVEs, urging patches
securityaffairs.com
-
WordPress SQLi bug allows remote code execution, update now
securityonline.info
-
WordPress REST API flaw lets attackers run code remotely
www.rapid7.com