Vulnerability intelligence
CVE-2026-63030
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
98%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-21
Remediation
Patch available
Federal deadline 2026-07-24
12 articles across 8 outlets · first covered Jul 17, 2026 · latest Jul 27, 2026
Coverage timeline
-
UK firms must patch now as CISA flags six active exploitssecurityonline.info · Jul 27, 2026
-
CISA adds DDWRT, Langflow and WordPress bugs to KEV listsecurityaffairs.com · Jul 22, 2026
-
CISA warns of active exploits in WordPress, Langflow, DDWRTsecurityonline.info · Jul 21, 2026
-
CISA Warns of Critical WordPress Flaw CVE‑2026-63030 in KEVcisa.gov · Jul 21, 2026
-
Critical WordPress Bug Lets Attackers Run Code Remotelysecurityonline.info · Jul 21, 2026
-
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeoverwww.darkreading.com · Jul 20, 2026
-
WordPress core flaw CVE-2026-63030 lets attackers execute codeisc.sans.edu · Jul 20, 2026
-
AI crafted WordPress exploit chain triggers urgent CVE patcheswww.infosecurity-magazine.com · Jul 20, 2026
-
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCEwww.securityweek.com · Jul 20, 2026
-
Public PoC exploits hit critical WordPress CVEs, urging patchessecurityaffairs.com · Jul 19, 2026
-
WordPress SQLi bug allows remote code execution, update nowsecurityonline.info · Jul 18, 2026
-
WordPress REST API flaw lets attackers run code remotelywww.rapid7.com · Jul 17, 2026