MEDIUMVulnerability
Global

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

·Source: SANS ISC

Updated:

Executive Summary

Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated

Analysis

Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.

Indicators of Compromise (1)

CVE (1)
CVE-2026-63030
Source Attribution

Originally published by SANS ISC on Jul 20, 2026.

Related Threats