logo

Inside wp2shell: How Two WordPress Core Bugs Became a Critical RCE Chain

ID: db3c54d0-e599-5201-824d-e915d8290536

STIX ID: report--db3c54d0-e599-5201-824d-e915d8290536

Feed Name: ThreatMon

Threat Score
70/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

Author: admin

...
...

This report describes a multi-stage attack abusing CVE-2026-63030 in WordPress: an authorization bypass in the REST API permits triggering an SQL injection through the author__not_in parameter, enabling exfiltration of database records (user credentials, password hashes, API keys, configuration) and escalation to administrative access, after which attackers can achieve remote code execution via standard WordPress administrative features.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.