← back
CVE-2026-63030criticalunder attackCWE-436

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 39%
from disclosure to weapon0 days
Published on NVDJul 17
1st PoCJul 17
CISA KEV+4d
exploitation probability
39%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
98 public exploit(s)
Action required by CISAfederal deadline: 2026-07-24

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

WordPress versions before 6.9.5 and 7.0.2 have a flaw in their REST API batch endpoint that can be exploited together with another SQL injection vulnerability to let attackers run malicious code on the website.

Technical detail

The vulnerability exploits route confusion in the REST API batch endpoint combined with SQL injection via author__not_in parameter in WP_Query to achieve arbitrary code execution. Requires network access to the WordPress REST API endpoint; attackers can bypass intended restrictions and inject SQL commands that lead to RCE.

Summary generated and translated by AI from the official description.
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
WordPress · WordPress
public PoCs found98
githubgithub.com/Icex0/wp2shell-poc488githubgithub.com/0xsha/wp2shell59githubgithub.com/dinosn/wp2shell-lab37githubgithub.com/ZephrFish/wp2shell-scanner23githubgithub.com/47Cid/wp2shell-lab13githubgithub.com/NULL200OK/WP2Shell10githubgithub.com/4minx/CVE-2026-630308githubgithub.com/bahartanir/wp2shell-scanner7githubgithub.com/mcipekci/wp2shell7githubgithub.com/ekomsSavior/wp2shell7githubgithub.com/ikow/wp2shell7githubgithub.com/mhtsec/CVE-2026-630307githubgithub.com/attackercan/wp2shell-poc26githubgithub.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t5githubgithub.com/own2pwn-fr/wp2shell-detect5githubgithub.com/securelayer7/WordPresShell5githubgithub.com/Senanfurkan/wordpress-cve-2026-630304githubgithub.com/mverschu/CVE-2026-630304githubgithub.com/fullhunt/wp2shell-scan4githubgithub.com/Lutfifakee-Project/wp2shell4githubgithub.com/OffByOn3/CVE-2026-63030-Wp2Shell4githubgithub.com/GhostInExile/CVE-2026-63030-Wp2Shell4githubgithub.com/JohenLastGen-JLG/wp2shell2githubgithub.com/InstaWP/wp2shell-scan2githubgithub.com/ebrasha/abdal-cve-2026-630302githubgithub.com/0xWhoknows/wp2shell1githubgithub.com/gbrsh/CVE-2026-630301githubgithub.com/4B3R4M4-607D/CVE-2026-63030-POC1githubgithub.com/Crypto-Cat/wp2shell1githubgithub.com/administrator-01001/CVE-2026-630301githubgithub.com/joaovicdev/EXPLOIT-CVE-2026-630301githubgithub.com/0xjessie21/wp2shell-checker1githubgithub.com/SentinelXofficial/sxwp2shell1githubgithub.com/0xBlackash/CVE-2026-630301githubgithub.com/lucifer0xf/wp2shell-Wordpress-TOWN1githubgithub.com/Ch4120N/CVE-2026-630301githubgithub.com/Lukols-Dev/wp-cve-2026-63030-check0githubgithub.com/tcyph3r/wp2shell-cve-2026-63030-root-cause0githubgithub.com/kulichr/wp2shell0githubgithub.com/CybersecSpirit/CVE-2026-630300githubgithub.com/0xh7ml/CVE-2026-630300githubgithub.com/mrx-arafat/CVE-2026-63030-POC0githubgithub.com/zi3lak/wp2shell_scanner0githubgithub.com/ChiefYoru/CVE-2026-63030_PoC0githubgithub.com/c0gnit00/Wp2Shell0githubgithub.com/TomorrowX6/CVE-2026-63030-poc0githubgithub.com/eyesecurity/wp2shell-compromise-scanner-plugin0githubgithub.com/hidden-investigations/wp2shell-scanner0githubgithub.com/ananay/wp2shell-lab0githubgithub.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-630300githubgithub.com/vulnquest58/PressVector0githubgithub.com/ZenithGenius/wordpress-batch-rce-lab0githubgithub.com/wn-iqbal/wp2shell0githubgithub.com/ASYquan/wp2shell-cf-WAF-bypass0githubgithub.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC0githubgithub.com/Adrees-Basheer/wp2shell-vulnerability-scanner0githubgithub.com/raphy76/wp2shell-poc-fulljs0githubgithub.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc0vulncheckvulncheck.com/xdb/8dbd04a4715cunverifiedvulncheckvulncheck.com/xdb/8c29f2e09796unverifiedvulncheckvulncheck.com/xdb/ef1c955d04acunverifiedvulncheckvulncheck.com/xdb/0e155f021cb0unverifiedvulncheckvulncheck.com/xdb/9dca80693885unverifiedvulncheckvulncheck.com/xdb/c229388b4517unverifiedvulncheckvulncheck.com/xdb/510f91fde2edunverifiedvulncheckvulncheck.com/xdb/8e380a2c7e7eunverifiedvulncheckvulncheck.com/xdb/2c22ab77cd0aunverifiedvulncheckvulncheck.com/xdb/61034f32533aunverifiedvulncheckvulncheck.com/xdb/3ceb02ef656aunverifiedvulncheckvulncheck.com/xdb/16827e184acbunverifiedvulncheckvulncheck.com/xdb/7d95ef261acdunverifiedvulncheckvulncheck.com/xdb/3c96356b1386unverifiedvulncheckvulncheck.com/xdb/10808d9e73c0unverifiedvulncheckvulncheck.com/xdb/d747655380f6unverifiedvulncheckvulncheck.com/xdb/7babea7a47ddunverifiedvulncheckvulncheck.com/xdb/94e81da06661unverifiedvulncheckvulncheck.com/xdb/b53ae1b8dd32unverifiedvulncheckvulncheck.com/xdb/5a4dfe2f0910unverifiedvulncheckvulncheck.com/xdb/b733ce85b287unverifiedvulncheckvulncheck.com/xdb/b4b379bb0c8funverifiedvulncheckvulncheck.com/xdb/eab18983fb0cunverifiedvulncheckvulncheck.com/xdb/9549cbf43f25unverifiedvulncheckvulncheck.com/xdb/90adf004a285unverifiedvulncheckvulncheck.com/xdb/afadcf0f8e23unverifiedvulncheckvulncheck.com/xdb/771dab10adc6unverifiedvulncheckvulncheck.com/xdb/94d096ef3535unverifiedvulncheckvulncheck.com/xdb/7bb16a1ea945unverifiedvulncheckvulncheck.com/xdb/355109b3ef07unverifiedvulncheckvulncheck.com/xdb/a075ba6e6e67unverifiedvulncheckvulncheck.com/xdb/03aa0310e804unverifiedvulncheckvulncheck.com/xdb/215f44b8a7b9unverifiedvulncheckvulncheck.com/xdb/5908e23870ceunverifiedvulncheckvulncheck.com/xdb/e32cda881d69unverifiedvulncheckvulncheck.com/xdb/aad1b5a41723unverifiedvulncheckvulncheck.com/xdb/e7433f2d580cunverifiedvulncheckvulncheck.com/xdb/98c3d3a11ea8unverifiedvulncheckvulncheck.com/xdb/7eab346d6260unverifiedvulncheckvulncheck.com/xdb/1460088472dbunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.