daily cyber × ai intelligence

index

tagged

[CVE-2026-63030]

6 editions · 6 items

July 21, 2026

  • WordPress "wp2shell" is now being exploited in the wild with a public working exploit. SANS ISC confirms active exploitation began shortly after disclosure of CVE-2026-63030 (a WordPress core SQL injection) chained with CVE-2026-60137 for unauthenticated RCE, and Horizon3 published a technical breakdown plus remediation-verification guidance (earlier coverage). Patch to 6.9.5 / 7.0.2 immediately. SANS ISC, Horizon3, Dark Reading. (discussion). · Vulnerabilities & Exploits

in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live

July 20, 2026

  • wp2shell exploitation broadened in the wild. SecurityWeek confirmed active attacks against CVE-2026-63030 and CVE-2026-60137 shortly after disclosure, and NCSC-FI's Daniel Card reported live batch-route exploitation attempts (most failing against auto-patched or WAF-fronted sites; ~20% of a 3.5K-host sample was still unpatched). Eye Security published a defender's guide with forensic artifacts, a compromise-scanner plugin, and a browser extension to check patch status (SecurityWeek, PwnDefend, Eye Security) (earlier coverage). · Vulnerabilities & Exploits

in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap

July 19, 2026

  • WordPress "wp2shell" (CVE-2026-63030) is now weaponized. Multiple researchers — including Assetnote's hash_kitten and teams at calif.io and FullHunt — have reproduced the unauthenticated REST API batch-route confusion chain that yields RCE against default installs, and public PoCs are circulating. Advice has shifted from "patch" to "patch and consider vulnerable systems compromised." Fixed in WordPress 6.8.6, 6.9.5 and 7.0.2 (BleepingComputer, FullHunt analysis + scanner, NCSC-NL) (earlier coverage) (discussion). · Vulnerabilities & Exploits

in WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation

July 18, 2026

  • "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST /batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory. · Vulnerabilities & Exploits

in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All