CVE Details

CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability
Published: 2026-07-21 CVSS: 9.8 CRITICAL Product: WordPress Core Due Date: 2026-07-24

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • GhostTroops/TOP • ⭐ 733 • 2022-03-19 • Conf: 90.0%
  • TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things
  • Icex0/wp2shell-poc • ⭐ 455 • 2026-07-17 • Conf: 95.0%
  • wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
  • sergiointel/wp2shell-poc • ⭐ 91 • 2026-07-17 • Conf: 95.0%
  • Stock vulnerable wordpress RCE poc for wp2shell.
  • 0xsha/wp2shell • ⭐ 57 • 2026-07-18 • Conf: 98.0%
  • CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.8
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-63030
cveMetadata > assignerOrgId 1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName WPScan
cveMetadata > dateReserved 2026-07-17T17:17:24.474Z
cveMetadata > datePublished 2026-07-17T19:14:12.910Z
cveMetadata > dateUpdated 2026-07-21T15:55:26.098Z
containers > cna > providerMetadata > orgId 1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81
containers > cna > providerMetadata > shortName WPScan
containers > cna > providerMetadata > dateUpdated 2026-07-18T04:13:49.898Z
containers > cna > title WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-436 Interpretation Conflict
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > affected > 0 > vendor WordPress
containers > cna > affected > 0 > product WordPress
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version 6.9.0
containers > cna > affected > 0 > versions > 0 > lessThan 6.9.5
containers > cna > affected > 0 > versions > 0 > versionType semver
containers > cna > affected > 0 > versions > 1 > status affected
containers > cna > affected > 0 > versions > 1 > version 7.0.0
containers > cna > affected > 0 > versions > 1 > lessThan 7.0.2
containers > cna > affected > 0 > versions > 1 > versionType semver
containers > cna > affected > 0 > defaultStatus unaffected
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
containers > cna > references > 0 > url https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
containers > cna > references > 0 > tags > 0 vdb-entry
containers > cna > references > 0 > tags > 1 technical-description
containers > cna > references > 1 > url https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
containers > cna > references > 1 > tags > 0 release-notes
containers > cna > references > 1 > tags > 1 vendor-advisory
containers > cna > metrics > 0 > cvssV3_1 > version 3.1
containers > cna > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > cna > metrics > 0 > cvssV3_1 > baseScore 9.8
containers > cna > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > cna > credits > 0 > lang en
containers > cna > credits > 0 > value Adam Kues, Assetnote / Searchlight Cyber
containers > cna > credits > 0 > type finder
containers > cna > credits > 1 > lang en
containers > cna > credits > 1 > value WordPress Security Team
containers > cna > credits > 1 > type coordinator
containers > cna > source > discovery EXTERNAL
containers > cna > x_generator > engine WPScan CVE Generator
containers > adp > 0 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 0 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseScore 7.5
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseSeverity HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
containers > adp > 0 > metrics > 0 > cvssV3_1 > integrityImpact NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 0 > metrics > 0 > cvssV3_1 > availabilityImpact NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 0 > metrics > 1 > other > type ssvc
containers > adp > 0 > metrics > 1 > other > content > id CVE-2026-63030
containers > adp > 0 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 1 > other > content > options > 1 > Automatable yes
containers > adp > 0 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 1 > other > content > version 2.0.3
containers > adp > 0 > metrics > 1 > other > content > timestamp 2026-07-21T15:45:15.918337Z
containers > adp > 0 > metrics > 2 > other > type kev
containers > adp > 0 > metrics > 2 > other > content > dateAdded 2026-07-21
containers > adp > 0 > metrics > 2 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030
containers > adp > 0 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030
containers > adp > 0 > references > 0 > tags > 0 government-resource
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > cweId CWE-436
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > description CWE-436 Interpretation Conflict
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-07-21T15:55:26.098Z