• Sources: CISA KEV catalog, CVE-2026-63030 (NVD), Searchlight Cyber research
  • Summary: CISA updated its Known Exploited Vulnerabilities catalog to version 2026.07.21 (count 1651) on 2026-07-21, adding the two WordPress Core flaws that form the wp2shell chain: CVE-2026-63030, an interpretation conflict in the REST API batch endpoint, and CVE-2026-60137, a SQL injection. Chained, they let an unauthenticated attacker reach remote code execution on default WordPress installations. Affected core is 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, fixed in 6.9.5 and 7.0.2 on 2026-07-17. CISA set a federal remediation deadline of 2026-07-24 for CVE-2026-63030. The disclosure on 2026-07-17 reported no known exploitation, so the KEV addition marks that status changing to active. The same catalog update added CVE-2026-0770, an unauthenticated remote code execution flaw in Langflow (exec_globals handling in the validate endpoint, CVSS 9.8), and CVE-2021-27137, a DD-WRT stack buffer overflow.
  • Why it matters: WordPress runs a large share of public sites, and a pre-auth core RCE moving to confirmed active exploitation with a three-day federal deadline puts unpatched 6.9.x and 7.0.x installs at immediate risk.
  • Follow-up: Watch for mass scanning and ransomware follow-on against the /wp-json/batch/v1 endpoint, whether forced auto-updates reach installs without auto-update enabled, and whether the withheld exploit chain is fully published.

send feedback on this story