WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

ORIGINAL QUELLE:
isc.sans.edu

Quelle: SANSISC

Last week, Searchlight Cyber released details about a vulnerability they are calling „wp2shell“. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.

← Zurück zum security Archiv (20.07.2026)