WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Published: 2026-07-20
CVE-2026-63030 and CVE-2026-60137 form the wp2shell pre-auth RCE chain in WordPress Core. Exploitation confirmed. Patches in WordPress 7.0.2 and 6.9.5.
https://latesthackingnews.com/2026/07/26/wp2shell-vulnerability-wordpress-rce/
https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/
https://www.infosecurity-magazine.com/news/researchers-wordpress-exploit/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
https://github.com/DeadExpl0it/wp2shell-poc
https://github.com/iAm-182/wp-cve-alert
https://github.com/mhassani97/cve-2026-63030-lab
https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
https://github.com/g0d150ne/WP2Shell
https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass
https://github.com/AnggaTechI/CVE-2026-63030
https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC
https://github.com/rechandra/wp2exp-2026
https://github.com/x-znn/CVE-2026-63030
https://github.com/Procjevt/CVE-2026-63030
https://github.com/AdarshThakur14777-cyber/CVE-2026-60137
https://github.com/kayahalime/cve-enrichment-tool
https://github.com/johnlodan/wp2shell-rce
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/yuag/wp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
https://github.com/TadeasDitte/Rozhanitsy
https://github.com/shinthink/CVE-2026-63030
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/mcipekci/wp2shell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/0xjessie21/wp2shell-checker
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/Crypto-Cat/wp2shell
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/vulnquest58/PressVector
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/ananay/wp2shell-lab
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/bahartanir/wp2shell-scanner
https://github.com/ikow/wp2shell
https://github.com/c0gnit00/Wp2Shell
https://github.com/edenzaraf/wp2shell
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/mhtsec/CVE-2026-63030
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/securelayer7/WordPresShell
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/yoerivegt/wp2shell-poc
https://github.com/zi3lak/wp2shell_scanner
https://github.com/0xWhoknows/wp2shell
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/h4cd0c/wp2shell
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/0xsha/wp2shell
https://github.com/mverschu/CVE-2026-63030
https://github.com/4minx/CVE-2026-63030
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/kulichr/wp2shell
https://github.com/HaakimSec/zero2shell-50
https://github.com/NULL200OK/WP2Shell
https://github.com/ekomsSavior/wp2shell
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/47Cid/wp2shell-lab
https://github.com/dinosn/wp2shell-lab
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/Icex0/wp2shell-poc
https://github.com/nando0x0a/ThreatForge
https://github.com/Hector-Abarca/realrisk-checks
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030
Published: 2026-07-17
Updated: 2026-07-22
Named Vulnerability: wp2shellKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.97271
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest