CISA Known Exploited Vulnerability
CVE-2026-63030 — WordPress Actively Exploited CVE
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-202
CISA catalog entry
Product
Core
Vendor
WordPress
Added to KEV
2026-07-21
Remediation due
2026-07-24
What WebPulse reported · 3 analyses
Google Gives Threat Actors One Primary Name — and Keeps the Rest Searchable
A canonical-name-with-aliases system consolidates the post-Mandiant/TAG merger. WebPulse reads this as infrastructure for machine-speed triage.
July 27, 2026
Two WordPress Core Flaws Let Attackers Plant Plugins That Outlast Cleanup
CVE-2026-63030 and CVE-2026-60137 are being exploited to install persistent webshells through WordPress Core's plugin installer.
July 22, 2026
A WordPress RCE That Skips the Plugin Layer Entirely
Two chained CVEs enable pre-authenticated code execution on standard WordPress installs. Patches shipped July 17 — sites that haven't applied them are exposed.
July 22, 2026
Related vulnerabilities