WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
ID: 94ad9607-d11f-557a-8048-7eaaefb786fd
STIX ID: report--94ad9607-d11f-557a-8048-7eaaefb786fd
Feed Name: SANS ISC Diary
Searchlight Cyber disclosed a critical WordPress Core SQL injection vulnerability dubbed "wp2shell" (CVE-2026-63030) that allows unauthenticated RCE via the REST API and has been observed exploited in the wild; published exploit requests demonstrate a UNION-based SQLi that writes a PHP webshell to /var/www/wp-content/cache/94uh9ubh6e1x.php and attackers subsequently added admin users. The report includes decoded queries, raw exploit payloads captured by honeypots, and quick remediation/detection advice (check the cache directory and recently created users).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
