THREATOPS
THREAT OPSThreat News › WordPress Core Pre-Auth RCE Chain Exploited in the Wild

WordPress Core Pre-Auth RCE Chain Exploited in the Wild

loworca_securityPublished 2026-07-22

<p>A critical vulnerability chain combining CVE-2026-63030 (CVSS 9.8) and CVE-2026-60137 (CVSS 5.9) was disclosed affecting WordPress Core, allowing attackers to achieve unauthenticated remote code execution via chained REST API batch-route confusion and SQL injection flaws. Due to the potential for full server compromise on default installations, immediate patching is required. About CVE-2026-630

Indicators of compromise

Original source: https://orca.security/resources/blog/wordpress-core-pre-auth-rce-chain/