Skip to content
CISA Known Exploited Vulnerability

CVE-2026-63030 — WordPress Actively Exploited CVE

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-202

⚠ Actively exploited (CISA KEV) WordPress 2026
CISA catalog entry
Product
Core
Vendor
WordPress
Added to KEV
2026-07-21
Remediation due
2026-07-24