CVE-2026-63030 · Critical · CISA KEV
WordPress Core SQLi/RCE: Critical Vulnerability Exploited in the Wild
Threat Engine Auto-Feed · data current as of 2026-07-22
A critical interpretation conflict vulnerability in WordPress Core (CVE-2026-63030) allows for SQL Injection and Remote Code Execution. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA KEV, and has a high EPSS percentile, indicating a significant likelihood of future exploitation.
- CVSS:
- EPSS percentile: 0.98425
- Exploitation pressure: 84/100 (Critical)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 98th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability stems from an 'interpretation conflict,' where different parts of the system process or interpret data in conflicting ways. This can lead to unexpected behavior, such as allowing an attacker to inject malicious SQL queries or execute arbitrary code remotely.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using WordPress Core, particularly those in financial services and technology sectors, due to documented adversary targeting.
- Any enterprise relying on WordPress for critical operations or public-facing content.
Misconfigurations that escalate it
- Outdated WordPress Core installations.
- Lack of robust input validation and output encoding practices.
High-impact scenarios
- Full compromise of WordPress sites, leading to data theft, website defacement, or use as a platform for further attacks.
- Remote Code Execution, allowing attackers to gain control over the underlying server.
- SQL Injection, enabling unauthorized access to, modification of, or deletion of database contents.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor WordPress access logs for unusual activity, especially related to SQL queries or file modifications.
- Implement Web Application Firewalls (WAFs) to detect and block SQL Injection attempts.
- Regularly scan WordPress installations for known vulnerabilities and indicators of compromise.
Contain
- Isolate affected WordPress instances from the network to prevent lateral movement.
- Block suspicious IP addresses identified in logs at the network perimeter.
Patch
- Apply the latest security patches for WordPress Core immediately upon release.
Frontier verdict — Critical
This is a critical vulnerability in WordPress Core, actively exploited in the wild, requiring immediate patching to prevent SQL Injection and Remote Code Execution.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.