SQL Injection and Remote Code Execution in WordPress REST API
CVE-2026-63030

9.8CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
17 July 2026

Badges

🥇 Trended No. 1📈 Trended📈 Score: 36,400👾 Exploit Exists🟡 Public PoC🟣 EPSS 98%🦅 CISA Reported📰 News Worthy

What is CVE-2026-63030?

CVE-2026-63030 is a significant vulnerability found in the WordPress content management system, specifically affecting versions 6.9.x prior to 6.9.5 and 7.0.x before 7.0.2. This vulnerability stems from a critical issue within the REST API, where a batch endpoint route confusion could be exploited. When combined with an existing SQL Injection vulnerability in the WP_Query function, designated CVE-2026-60137, this flaw allows attackers to execute arbitrary SQL commands and potentially achieve Remote Code Execution (RCE). The implications of this vulnerability are severe as WordPress powers a substantial percentage of websites globally, making it an attractive target for malicious actors. If successfully exploited, this could lead to complete control over the WordPress installation, enabling attackers to manipulate data, steal sensitive information, or deploy further malicious software.

Potential impact of CVE-2026-63030

  1. Data Breach Risk: Exploiting this vulnerability could allow unauthorized access to sensitive user data, including personal information and login credentials, leading to potential data breaches that could affect both the organization and its users.

  2. Website Defacement and Downtime: With Remote Code Execution capabilities, attackers can alter website content, leading to defacement or the introduction of malicious scripts. This could result in significant downtime, loss of customer trust, and reputational damage.

  3. Undetected Malware Deployment: Attackers can utilize this vulnerability to install backdoors or other forms of malware, enabling persistent access to compromised systems. This ongoing threat could facilitate further attacks, including the potential for ransomware deployment, significantly impacting organizational operations and security.

CISA has reported CVE-2026-63030

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-63030 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

WordPress 6.9.0 < 6.9.5

WordPress 7.0.0 < 7.0.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild - IT Security News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,…Read ...

2 weeks ago

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

CISA warns that an actively exploited WordPress Core SQL injection flaw could compromise websites and potentially enable remote code execution.

2 weeks ago

Hackers Exploit Newly Patched WordPress Vulnerabilities

Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.

3 weeks ago

References

EPSS Score

98% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🦅

    CISA Reported

  • 🥇

    Vulnerability reached the number 1 worldwide trending spot

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by It Security News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Kues, Assetnote / Searchlight Cyber
WordPress Security Team
.