Known vulnerability record
CVE-2026-63030
WordPress Core Interpretation Conflict Vulnerability
Summary
WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Signals
Keep the signals separate
CVSS severitycriticalScore 9.8 · source WPScan
EPSS probability95.6%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-07-21
Ransomware useunknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2026-07-17
- CVE modified
- 2026-07-22
- KEV date added
- 2026-07-21
- Dataset fetched
- 2026-08-21T03:55:02.679Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2026-63030 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2026-63030 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.