• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-63030: pre-auth remote code execution in WordPress Core

An unauthenticated attacker can achieve remote code execution against WordPress Core via a REST API route confusion that enables SQL injection chaining (CVE-2026-63030). Affected releases are 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1; vendors fixed the issue in 6.9.5 and 7.0.2. Exploitation requires network access to the WordPress REST API and may be combined with a separate SQL injection flaw to escalate impact; no user interaction or valid account is required to trigger the issue.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.10119
CWE
CWE-436
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a July 24, 2026 remediation deadline, and public exploit code exists — prioritize immediate mitigation or upgrade.

What is CVE-2026-63030?

An unauthenticated attacker can achieve remote code execution against WordPress Core via a REST API route confusion that enables SQL injection chaining (CVE-2026-63030). Affected releases are 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1; vendors fixed the issue in 6.9.5 and 7.0.2. Exploitation requires network access to the WordPress REST API and may be combined with a separate SQL injection flaw to escalate impact; no user interaction or valid account is required to trigger the issue.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of WordPress Core are affected?

BRANCHAFFECTEDFIXED
6.x6.9.0 – before 6.9.56.9.5
7.x7.0.0 – before 7.0.27.0.2

Is CVE-2026-63030 being exploited?

CISA added CVE-2026-63030 to the Known Exploited Vulnerabilities catalog on 2026-07-21; U.S. federal agencies were required to remediate by 2026-07-24. Public exploit code is available.

How to fix CVE-2026-63030

  1. Upgrade WordPress Core to 6.9.5 or later, or to 7.0.2 or later.
  2. If you cannot upgrade immediately, restrict access to the REST API and block untrusted network access to WordPress endpoints.
  3. Follow WordPress vendor guidance and apply any recommended mitigations or configuration changes.
  4. Monitor webserver and application logs for suspicious REST API traffic and SQL-query anomalies.

Frequently asked questions

Is CVE-2026-63030 being actively exploited?

CVE-2026-63030 was added to CISA’s Known Exploited Vulnerabilities catalog on 2026-07-21 and U.S. federal agencies were required to remediate by 2026-07-24; public exploit code is available.

Which WordPress Core versions are affected by CVE-2026-63030?

WordPress Core releases 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected; fixes are included in 6.9.5 and 7.0.2.

Is there a patch for CVE-2026-63030?

Yes. WordPress published fixes in versions 6.9.5 and 7.0.2; apply those updates per your update procedures.

Does CVE-2026-63030 require authentication?

No. The vulnerability can be exploited without valid credentials, requiring only network access to the WordPress REST API and, in many cases, chaining with a related SQL injection issue.

References