SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 6,898 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 6,898 new IOCs ingested in last 24h

CVE-2026-63030

Published: 2026-07-17Modified: 2026-07-18
9.8
CVSS v3
8.9%
EPSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules3
Rules tagged with this CVE
criticalWordPress Wp2shell Webshell Plugin Access——
highWordPress Wp2shell Exploitation Tool User-Agent——
mediumWordPress Wp2shell REST Batch Endpoint Exploitation——
🛠️ Patch Details0
Affected/fixed versions from threat intel reports
No specific version data extracted yet.
📰 Threat Intel Coverage0
Digest reports mentioning this CVE
No threat intel digest coverage found.