[KEV] CVE-2026-63030 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-63030 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-63030 is an interpretation conflict vulnerability in WordPress Core that may allow an attacker to conduct SQL injection and obtain remote code execution.
Technical Detail
The flaw arises from inconsistent interpretation of attacker-controlled input within WordPress Core. An attacker may be able to exploit the conflict to inject SQL commands into backend database queries. Successful exploitation could expose or modify database data and, when chained with CVE-2026-60137, result in remote code execution on the affected WordPress environment.
Exploitation Status
Exploit maturity is assessed as Operational, meaning exploitation capability is available for use in real-world intrusion activity. CISA has confirmed active exploitation in the wild. CVE-2026-63030 was added to the CISA Known Exploited Vulnerabilities Catalog on July 21, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Treat this as an urgent patching priority for all WordPress Core deployments. Apply the vendor-provided WordPress Core security update as soon as it is available, and ensure that CVE-2026-60137 is also remediated because the vulnerabilities may be chained for remote code execution. For CISA Binding Operational Directive requirements, patch by the KEV remediation due date or apply mitigations; the specific due date is not provided in the available data. Review WordPress, web server, and database logs for unusual requests, SQL errors, unexpected administrative activity, unauthorized plugin or theme changes, and unrecognized PHP files or processes. Restrict administrative access, maintain tested backups, and investigate signs of database manipulation or unauthorized code execution.