CISA has added CVE‑2026-63030 to its Known Exploited Vulnerabilities catalogue. The entry concerns WordPress Core and describes an interpretation conflict vulnerability that could enable an attacker to perform SQL injection and achieve remote code execution, a flaw that can be chained with CVE‑2026-60137.
The vulnerability is classified as an interpretation conflict leading to SQL injection and subsequent remote code execution. It carries a CVSS score of 9.8, rating it as critical. No patch or advisory is currently listed as available, and the patch status is marked as unknown.
Active exploitation has been confirmed, which is why the CVE was placed in the KEV catalogue. There is no publicly known use of this vulnerability in ransomware campaigns at this time. CISA has set a remediation deadline of 26 July 2026 for federal civilian executive branch agencies.
CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset’s internet exposure and adhere to BOD 26‑04 patching guidelines. While the directive binds FCEB agencies, all organisations should review their exposure to this flaw.
For full details, consult the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-63030 and the CISA KEV catalogue at https://www.cisa.gov/known-exploited-vulnerabilities-catalog.