CVE-2026-63030
- CVSS
- —
- EPSS
- 0.101 (95.5th percentile)
- CISA KEV
- Added 2026-07-21, due 2026-07-24
- Exploitation
- No report
- Public exploits
- 75 repositories
- State
- Unknown
Coverage

Actively exploitedCritical 85Wiz Research
Exploitation in the Wild of wp2shell
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations.
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev