WordPress Core SQL Injection Vulnerability CVE-2026-63030 Exploited
A critical SQL injection vulnerability identified as CVE-2026-63030 affects WordPress Core and is actively exploited, allowing unauthenticated remote code execution.
Tag
4 results in the archive.
A critical SQL injection vulnerability identified as CVE-2026-63030 affects WordPress Core and is actively exploited, allowing unauthenticated remote code execution.
A critical vulnerability in WordPress core enables unauthenticated attackers to execute code on default installations, prompting urgent patch releases.
A hacker group's exposed server revealed tools, logs, and a target list of over 1.4 million WordPress sites, exposing a large-scale WordPress backdoor campaign.
Attackers compromised ShapedPlugin's build pipeline to inject backdoor code into Pro plugins via official update channels. This supply chain attack puts thousands of WordPress sites at risk of remote exploitation.