DIRAS TAKE
Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a July 24, 2026 remediation deadline, and public exploit code exists — prioritize immediate mitigation or upgrade.
What is CVE-2026-63030?
An unauthenticated attacker can achieve remote code execution against WordPress Core via a REST API route confusion that enables SQL injection chaining (CVE-2026-63030). Affected releases are 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1; vendors fixed the issue in 6.9.5 and 7.0.2. Exploitation requires network access to the WordPress REST API and may be combined with a separate SQL injection flaw to escalate impact; no user interaction or valid account is required to trigger the issue.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of WordPress Core are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 6.x | 6.9.0 – before 6.9.5 | 6.9.5 |
| 7.x | 7.0.0 – before 7.0.2 | 7.0.2 |
Is CVE-2026-63030 being exploited?
CISA added CVE-2026-63030 to the Known Exploited Vulnerabilities catalog on 2026-07-21; U.S. federal agencies were required to remediate by 2026-07-24. Public exploit code is available.
How to fix CVE-2026-63030
- Upgrade WordPress Core to 6.9.5 or later, or to 7.0.2 or later.
- If you cannot upgrade immediately, restrict access to the REST API and block untrusted network access to WordPress endpoints.
- Follow WordPress vendor guidance and apply any recommended mitigations or configuration changes.
- Monitor webserver and application logs for suspicious REST API traffic and SQL-query anomalies.
Frequently asked questions
Is CVE-2026-63030 being actively exploited?
CVE-2026-63030 was added to CISA’s Known Exploited Vulnerabilities catalog on 2026-07-21 and U.S. federal agencies were required to remediate by 2026-07-24; public exploit code is available.
Which WordPress Core versions are affected by CVE-2026-63030?
WordPress Core releases 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected; fixes are included in 6.9.5 and 7.0.2.
Is there a patch for CVE-2026-63030?
Yes. WordPress published fixes in versions 6.9.5 and 7.0.2; apply those updates per your update procedures.
Does CVE-2026-63030 require authentication?
No. The vulnerability can be exploited without valid credentials, requiring only network access to the WordPress REST API and, in many cases, chaining with a related SQL injection issue.
References
- nvd.nist.gov/vuln/detail/CVE-2026-63030
- cve.org/CVERecord?id=CVE-2026-63030
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030
- github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
- wordpress.org/news/2026/07/wordpress-7-0-2-release
- All WordPress CVEs on CVE Radar
- CVEs published in September 2026