
New WordPress Vulnerability CVE-2026-63030 Allows Unauthenticated Remote Code Execution
WordPressvulnerabilityCVE-2026-63030SQL injectionremote code executionTryHackMecybersecurity
A new vulnerability, CVE-2026-63030, was disclosed on Friday. It affects WordPress and allows unauthenticated attackers to exploit the REST API via SQL injection, forge an admin account, and achieve remote code execution without requiring credentials. The post mentions a dedicated training room, WP2Shell, created to demonstrate the full exploit chain and mitigation steps. The room is currently available on TryHackMe’s MAX platform.