CuraSec

Act archived

WordPress Core SQL Injection (CVE-2026-63030) Under Active Exploitation

2026-07-21 12:43 UTC · SANS ISC · read the source ↗ #wordpress#rce#sql-injection
  • Engineer — Act: Unauthenticated RCE in WordPress Core (not a plugin) is being actively exploited with a public PoC on GitHub — patch all WordPress Core installations to the latest fixed release immediately and audit web server and DB logs for SQLi patterns.
  • SOC/IR — Act: Active exploitation is confirmed; sweep any WordPress-hosting infrastructure for webshells, unexpected file writes, and anomalous database query patterns tied to wp2shell activity since last week’s disclosure.
  • Leader — Plan: Confirm whether WordPress is present in the company’s web estate and verify engineering has prioritized patching this week; not yet at board-briefing scale but unauthenticated RCE with active exploitation warrants prompt follow-up with the engineering team.
  • Signals: CVE-2026-63030 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.