
Public Exploit Released for WordPress Core Pre-Auth RCE Vulnerability (CVE-2026-63030)
WordPressRCEvulnerabilityCVE-2026-63030CVE-2026-60137exploitGitHubauthentication_bypassSQL_injectionsecurity
A public exploit for the WordPress core pre-authentication remote code execution (RCE) vulnerability (CVE-2026-63030) is now available on GitHub under an MIT license. The exploit chains CVE-2026-63030 (REST batch-route confusion leading to auth bypass) with CVE-2026-60137 (SQL injection in WP_Query author__not_in) to achieve RCE without requiring plugins or authentication. The vulnerability affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, with fixes released in versions 7.0.2, 6.9.5, and 6.8.6. Auto-updates have been enforced for affected installations.