2026 Q2 Threat Report: Track the Threats Shaping Enterprise Risk

CVE-2026-63030

Understanding CVE-2026-63030: The WordPress REST API Flaw Behind wp2shell 

CVSS Gauge
CVSS Needle

Summary

CVE-2026-63030 is a critical WordPress REST API batch endpoint flaw affecting versions 6.9.0 – 6.9.4 and 7.0.0 – 7.0.1. When chained with CVE-2026-60137, it forms the wp2shell exploit, allowing unauthenticated remote code execution. Active exploitation was observed shortly after disclosure, prompting emergency security updates.

Urgent Actions Required

Which Systems Are Vulnerable to CVE-2026-63030?

Technical Overview 

How Does the CVE-2026-63030 Exploit Work?

The attack typically follows these steps:

CVE-2026-63030

What Causes CVE-2026-63030?

Vulnerability Root Cause:   

CVE-2026-63030 is caused by a logic flaw in the WordPress REST API batch endpoint. During batch request processing, validation and request execution can become misaligned, causing requests to be handled by the wrong internal route. This route confusion allows permission checks to be bypassed. While the flaw alone does not lead to remote code execution, it can be chained with CVE-2026-60137, a SQL injection vulnerability, to form the wp2shell exploit chain that enables unauthenticated remote code execution on affected WordPress installations.

How Can You Mitigate CVE-2026-63030?

If immediate patching is delayed or not possible: 

  • Block /wp-json/batch/v1 (or ?rest_route=/batch/v1) at the WAF.
  • Restrict anonymous REST API access.
  • Enable WAF protections to block exploit attempts.
  • Apply the official WordPress update as soon as possible.

Which Assets and Systems Are at Risk?

Will Patching CVE-2026-63030 Cause Downtime?

Patch application impact: Low. Update to WordPress 6.9.5 or 7.0.2. Verify the update completed successfully. 

How Can You Detect CVE-2026-63030 Exploitation?

Exploitation Signatures:

  • Unusual requests targeting the /wp-json/batch/v1 endpoint or ?rest_route=/batch/v1
  • HTTP access logs showing anomalous REST API batch endpoint requests
  • High-volume scanning or repeated exploitation attempts against vulnerable WordPress sites

Indicators of Compromise (IOCs/IOAs):

Behavioral Indicators:

Alerting Strategy:

See How Fidelis Elevate® Helps Stop Threats Before They Spread

      • Discover the capabilities of an Open and Active XDR platform
      • Learn how unified network, endpoint, deception, and AD protection improves detection
      • See how proactive threat detection accelerates incident response
Download the Data Sheet

CVSS Breakdown Table 

MetricValue Description
Base Score9.8Indicates a critical vulnerability with severe potential impact
Attack VectorNetworkCan be exploited remotely over the network
Attack ComplexityLowNo special conditions are required for exploitation
Privileges RequiredNoneThe attack does not require authentication
User Interaction NoneNo user action is needed to trigger the vulnerability
Scope Unchanged The impact remains within the vulnerable WordPress component
Confidentiality Impact HighAn attacker can gain access to sensitive information
Integrity Impact HighAn attacker can modify data or system components
Availability ImpactHighSuccessful exploitation can severely affect service availability

Related Readings

One Platform for All Adversaries

See Fidelis in action. Learn how our fast and scalable platforms provide full visibility, deep insights, and rapid response to help security teams across the World protect, detect, respond, and neutralize advanced cyber adversaries.