CVE-2026-63030

high

Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

From the Tenable Blog

wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable®
wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable®

Published: 2026-07-20

CVE-2026-63030 and CVE-2026-60137 form the wp2shell pre-auth RCE chain in WordPress Core. Exploitation confirmed. Patches in WordPress 7.0.2 and 6.9.5.

References

https://github.com/DeadExpl0it/wp2shell-poc

https://github.com/iAm-182/wp-cve-alert

https://github.com/mhassani97/cve-2026-63030-lab

https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-

https://github.com/g0d150ne/WP2Shell

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC

https://github.com/rechandra/wp2exp-2026

https://github.com/x-znn/CVE-2026-63030

https://github.com/Procjevt/CVE-2026-63030

https://github.com/AdarshThakur14777-cyber/CVE-2026-60137

https://github.com/kayahalime/cve-enrichment-tool

https://github.com/johnlodan/wp2shell-rce

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/yuag/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/TadeasDitte/Rozhanitsy

https://github.com/shinthink/CVE-2026-63030

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/mcipekci/wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/0xjessie21/wp2shell-checker

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/vulnquest58/PressVector

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/ananay/wp2shell-lab

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ikow/wp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/edenzaraf/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/mhtsec/CVE-2026-63030

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/securelayer7/WordPresShell

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/yoerivegt/wp2shell-poc

https://github.com/zi3lak/wp2shell_scanner

https://github.com/0xWhoknows/wp2shell

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/h4cd0c/wp2shell

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/0xsha/wp2shell

https://github.com/mverschu/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/kulichr/wp2shell

https://github.com/HaakimSec/zero2shell-50

https://github.com/NULL200OK/WP2Shell

https://github.com/ekomsSavior/wp2shell

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/dinosn/wp2shell-lab

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Icex0/wp2shell-poc

https://github.com/nando0x0a/ThreatForge

https://github.com/Hector-Abarca/realrisk-checks

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030

Details

Source: Mitre, NVD

Published: 2026-07-17

Updated: 2026-07-22

Named Vulnerability: wp2shellKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.97271

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest