Critical WordPress Core Flaw (CVE-2026-63030) Enables Unauthenticated RCE
A critical vulnerability in WordPress Core (CVE-2026-63030) allows unauthenticated remote code execution. Versions before 6.9.5 and 7.0.2 are affected.
What happened
The vulnerability, tracked as CVE-2026-63030, is a SQL injection flaw in WordPress Core that can be exploited to achieve unauthenticated remote code execution. According to SANS ISC, exploitation of this vulnerability has already begun. The exploit attempts observed target the REST API endpoint /wp/v2/posts with a specifically crafted payload.
The National Vulnerability Database lists several other critical vulnerabilities (CVE-2026-13439, CVE-2026-14282, CVE-2026-15011, CVE-2026-15015, CVE-2026-15981, CVE-2026-65048, CVE-2026-65049) affecting various WordPress plugins, but the core flaw (CVE-2026-63030) is the most severe as it impacts the WordPress platform itself.
To mitigate the risk, it is recommended to upgrade WordPress to version 6.9.5 or 7.0.2. Additionally, users should review the NVD entries for the plugin vulnerabilities and apply necessary updates to those components as well. For more details, consult the primary sources listed.
How 0Day mitigates this
wordpress is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.