Skip to content
COOEY

EXPOSURES › CVE-2026-63030

CVE-2026-63030

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-63030 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 rceexploited-in-wildransomware-linkedunpatched

WordPress 6.6.11 exposed to RCE via unhandled input

Authenticated attackers with contributor access could inject scripts, leading to RCE in WordPress 6.6.11 and below.

Shame score — Massive exposure of WordPress users to remote code execution due to severe input sanitization and output escaping issues.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.