CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution.

This flaw, tracked as CVE-2026-63030, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026. This designation signals confirmed in-the-wild exploitation and an urgent risk for organizations that rely on WordPress.

The vulnerability arises from an interpretation conflict within WordPress Core, which is categorized under CWE-436. This flaw creates inconsistencies in how input is processed, enabling the injection and execution of malicious SQL queries.

Attackers can exploit this issue to manipulate backend database queries, potentially exposing sensitive data or altering the application’s behavior.

WordPress Core SQL Injection Vulnerability Exploited

Researchers warn that CVE-2026-63030, dubbed wp2shell, becomes more dangerous when chained with CVE-2026-60137, a SQL injection flaw classified as CWE-89. It occurs when plugins or themes pass untrusted user input into database queries without proper sanitization.

While SQL injection vulnerabilities often stem from insecure coding practices in extensions, this particular case is severe because it affects default WordPress installations when exploited in conjunction with the core flaw.

When these vulnerabilities are chained together, they may allow unauthenticated attackers to escalate from SQL injection to full remote code execution.

This means that threat actors could potentially take complete control of affected WordPress websites without needing valid credentials.

Such access could be used to deploy web shells, inject malicious scripts, redirect users to phishing pages, or utilize compromised servers for further attacks.

Although CISA has not confirmed whether these vulnerabilities are being used in ransomware campaigns, the agency emphasizes that active exploitation has already been observed.

Given that WordPress powers a significant portion of the internet, the attack surface is substantial, making this vulnerability particularly attractive to both opportunistic and advanced threat actors.

CISA has mandated that federal agencies remediate CVE-2026-63030 by July 24, 2026, and CVE-2026-60137 by August 4, 2026, under Binding Operational Directive (BOD) 26-04.

This directive prioritizes patching based on risk and requires organizations to take immediate action to secure vulnerable systems. The agency also advises following its Forensic Triage Requirements to detect potential compromises and assess the impact of exploitation.

WordPress site administrators and security teams are strongly urged to apply vendor-provided patches as soon as they become available.

If mitigations are not yet released, organizations should evaluate their exposure, restrict access to critical systems, and consider temporarily turning off vulnerable components. Monitoring database queries, web server logs, and unusual administrative activity can help identify signs of exploitation.

This incident highlights the ongoing risk posed by core application vulnerabilities combined with insecure plugin or theme behavior. It underscores the importance of adopting defense-in-depth strategies, including strict input validation, web application firewalls, and continuous vulnerability management.

With active exploitation confirmed, the WordPress ecosystem is facing a critical security moment. Organizations that delay remediation risk complete site compromise, data breaches, and potential downstream attacks that could affect users and customers.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment