SQL Injection and Remote Code Execution in WordPress REST API
CVE-2026-63030
Key Information:
Badges
What is CVE-2026-63030?
CVE-2026-63030 is a significant vulnerability found in the WordPress content management system, specifically affecting versions 6.9.x prior to 6.9.5 and 7.0.x before 7.0.2. This vulnerability stems from a critical issue within the REST API, where a batch endpoint route confusion could be exploited. When combined with an existing SQL Injection vulnerability in the WP_Query function, designated CVE-2026-60137, this flaw allows attackers to execute arbitrary SQL commands and potentially achieve Remote Code Execution (RCE). The implications of this vulnerability are severe as WordPress powers a substantial percentage of websites globally, making it an attractive target for malicious actors. If successfully exploited, this could lead to complete control over the WordPress installation, enabling attackers to manipulate data, steal sensitive information, or deploy further malicious software.
Potential impact of CVE-2026-63030
-
Data Breach Risk: Exploiting this vulnerability could allow unauthorized access to sensitive user data, including personal information and login credentials, leading to potential data breaches that could affect both the organization and its users.
-
Website Defacement and Downtime: With Remote Code Execution capabilities, attackers can alter website content, leading to defacement or the introduction of malicious scripts. This could result in significant downtime, loss of customer trust, and reputational damage.
-
Undetected Malware Deployment: Attackers can utilize this vulnerability to install backdoors or other forms of malware, enabling persistent access to compromised systems. This ongoing threat could facilitate further attacks, including the potential for ransomware deployment, significantly impacting organizational operations and security.
CISA has reported CVE-2026-63030
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-63030 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
WordPress 6.9.0 < 6.9.5
WordPress 7.0.0 < 7.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild - IT Security News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,…Read ...
2 weeks ago
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
CISA warns that an actively exploited WordPress Core SQL injection flaw could compromise websites and potentially enable remote code execution.
2 weeks ago

Hackers Exploit Newly Patched WordPress Vulnerabilities
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.
3 weeks ago
References
EPSS Score
98% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🦅
CISA Reported
- 🥇
Vulnerability reached the number 1 worldwide trending spot
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by It Security News
Vulnerability published
Vulnerability Reserved