LOWVulnerability

CVE-2026-63030

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

Properties

product
Core
vulnerabilityName
WordPress Core Interpretation Conflict Vulnerability
epss_score
0.97271
cve_id
CVE-2026-63030
dueDate
2026-07-24
vendorProject
WordPress
requiredAction
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
dateAdded
2026-07-21
epss_percentile
0.99891

Related Entities (5)

DESCRIBES (1)

[KEVEntry]WordPress Core Interpretation Conflict Vulnerability

MENTIONED_IN (2)

[Campaign]Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
[Campaign]Exploitation in the Wild of wp2shell

ENRICHED_BY (1)

[Source]FIRST EPSS

KNOWN_EXPLOITED (1)

[Source]CISA KEV

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-63030 — Ninja Signal Threat Intelligence | Ninja Signal