EXPOSURES › CVE-2026-63030
CVE-2026-63030
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 90/100
rceexploited-in-wildransomware-linkedunpatched
WordPress 6.6.11 exposed to RCE via unhandled input
Authenticated attackers with contributor access could inject scripts, leading to RCE in WordPress 6.6.11 and below.
Shame score — Massive exposure of WordPress users to remote code execution due to severe input sanitization and output escaping issues.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.