WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
CVE-2026-63030, known as "wp2shell," is a critical SQL injection vulnerability in WordPress Core that allows unauthenticated remote code execution via the REST API. The vulnerability enables attackers to write a webshell file to the server and potentially add new admin users. Exploitation attempts began shortly after public disclosure. The exploit uses a UNION SQL injection in REST API requests to execute arbitrary PHP code. The malicious webshell disguises itself by returning a 404 error despite existing on the server. Users are advised to check for suspicious files in the /wp-content/cache/ directory and for unauthorized admin users.
AI Analysis
Technical Summary
CVE-2026-63030 is a SQL injection vulnerability in WordPress Core's REST API that permits unauthenticated remote code execution. The vulnerability is exploited by sending crafted POST requests to the REST API endpoint, leveraging UNION SELECT statements to inject PHP code that writes a webshell file to the server's cache directory. The webshell executes arbitrary system commands while returning a 404 error page to evade detection. Attackers have also used this exploit to create unauthorized admin users in the WordPress database. The vulnerability requires the REST API to be exposed and accessible. Exploit attempts have been observed shortly after the vulnerability was publicly disclosed.
Potential Impact
Successful exploitation of CVE-2026-63030 allows unauthenticated attackers to execute arbitrary code on the affected WordPress server. This can lead to full system compromise, including the ability to upload webshells, execute system commands, and create unauthorized administrative users. The presence of a stealthy webshell that returns false 404 errors complicates detection and remediation. The vulnerability affects WordPress Core, not plugins, increasing the potential attack surface. Exploitation is active in the wild shortly after disclosure.
Mitigation Recommendations
Patch status is not yet confirmed — check the official WordPress vendor advisory for current remediation guidance. Until a patch is available, users should assume compromise if vulnerable. Immediate mitigation includes verifying exposure of the REST API and restricting access if possible. Users should inspect the /wp-content/cache/ directory for suspicious PHP files such as '94uh9ubh6e1x.php' and remove any unauthorized files. Additionally, review the WordPress user database for recently created or unauthorized admin accounts and remove them. Monitor for unusual activity related to the REST API. Follow official WordPress security advisories for updates and patches.
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Description
CVE-2026-63030, known as "wp2shell," is a critical SQL injection vulnerability in WordPress Core that allows unauthenticated remote code execution via the REST API. The vulnerability enables attackers to write a webshell file to the server and potentially add new admin users. Exploitation attempts began shortly after public disclosure. The exploit uses a UNION SQL injection in REST API requests to execute arbitrary PHP code. The malicious webshell disguises itself by returning a 404 error despite existing on the server. Users are advised to check for suspicious files in the /wp-content/cache/ directory and for unauthorized admin users.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-63030 is a SQL injection vulnerability in WordPress Core's REST API that permits unauthenticated remote code execution. The vulnerability is exploited by sending crafted POST requests to the REST API endpoint, leveraging UNION SELECT statements to inject PHP code that writes a webshell file to the server's cache directory. The webshell executes arbitrary system commands while returning a 404 error page to evade detection. Attackers have also used this exploit to create unauthorized admin users in the WordPress database. The vulnerability requires the REST API to be exposed and accessible. Exploit attempts have been observed shortly after the vulnerability was publicly disclosed.
Potential Impact
Successful exploitation of CVE-2026-63030 allows unauthenticated attackers to execute arbitrary code on the affected WordPress server. This can lead to full system compromise, including the ability to upload webshells, execute system commands, and create unauthorized administrative users. The presence of a stealthy webshell that returns false 404 errors complicates detection and remediation. The vulnerability affects WordPress Core, not plugins, increasing the potential attack surface. Exploitation is active in the wild shortly after disclosure.
Mitigation Recommendations
Patch status is not yet confirmed — check the official WordPress vendor advisory for current remediation guidance. Until a patch is available, users should assume compromise if vulnerable. Immediate mitigation includes verifying exposure of the REST API and restricting access if possible. Users should inspect the /wp-content/cache/ directory for suspicious PHP files such as '94uh9ubh6e1x.php' and remove any unauthorized files. Additionally, review the WordPress user database for recently created or unauthorized admin accounts and remove them. Monitor for unusual activity related to the REST API. Follow official WordPress security advisories for updates and patches.
Technical Details
- Article Source
- {"url":"https://isc.sans.edu/diary/rss/33168","fetched":true,"fetchedAt":"2026-07-20T22:52:48.922Z","wordCount":498}
Threat ID: 6a5ea6c92a4a8d5989e4741c
Added to database: 07/20/2026, 22:52:57 UTC
Last enriched: 07/20/2026, 22:53:07 UTC
Last updated: 07/21/2026, 09:30:45 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.