WORDPRESS · JULY 2026 · CONFIRMED

Critical WordPress Core Flaw (CVE-2026-63030) Enables Unauthenticated RCE

CVE-2026-60137CVE-2026-63030Severity: HIGH

A critical vulnerability in WordPress Core (CVE-2026-63030) allows unauthenticated remote code execution. Versions before 6.9.5 and 7.0.2 are affected.

What happened

The vulnerability, tracked as CVE-2026-63030, is a SQL injection flaw in WordPress Core that can be exploited to achieve unauthenticated remote code execution. According to SANS ISC, exploitation of this vulnerability has already begun. The exploit attempts observed target the REST API endpoint /wp/v2/posts with a specifically crafted payload.

The National Vulnerability Database lists several other critical vulnerabilities (CVE-2026-13439, CVE-2026-14282, CVE-2026-15011, CVE-2026-15015, CVE-2026-15981, CVE-2026-65048, CVE-2026-65049) affecting various WordPress plugins, but the core flaw (CVE-2026-63030) is the most severe as it impacts the WordPress platform itself.

To mitigate the risk, it is recommended to upgrade WordPress to version 6.9.5 or 7.0.2. Additionally, users should review the NVD entries for the plugin vulnerabilities and apply necessary updates to those components as well. For more details, consult the primary sources listed.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If wordpress is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats