news.mlab.sh
3 results
threat-intel

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

A critical WordPress webshell vulnerability (CVE-2026-63030) is being actively exploited. This vulnerability, stemming from a SQL injection flaw in the WordPress Core REST API, allows unauthenticated remote code execution. The vulnerability was initially announced without a CVE number, but is now actively being used to…

SANS Internet Storm Center · Jul 20, 2026 Critical