Summary
This is a Remote Code Execution (RCE) vulnerability, CVE-2026-63030, affecting WordPress Core. It impacts WordPress Core versions 6.9.x, 7.0.x, and 7.1 beta releases earlier than 7.1 beta 2. Patches are available in WordPress 6.9.5, 7.0.2, and 7.1 beta 2. The vulnerability is known to be actively exploited in the wild, with public proof-of-concept exploits available.
Affected and patched versions
Affected Versions | Patched Versions |
|---|---|
WordPress Core 6.9.0 through 6.9.4 | WordPress Core 6.9.5 |
WordPress Core 7.0.0 through 7.0.1 | WordPress Core 7.0.2 |
WordPress Core 7.1 beta releases earlier than 7.1 beta 2 | WordPress Core 7.1 beta 2 |
Is my site vulnerable?
To determine if your WordPress site is vulnerable, check its installed version. You can find this information in a few ways.
The most straightforward method is to log into your WordPress administration area. Navigate to the "Dashboard" and then look for the "At a Glance" widget, which often displays your WordPress version. Alternatively, go to "Updates" in the left-hand menu; the current version is typically shown there.
If you cannot access the administration area, you can check the wp-includes/version.php file in your WordPress installation directory. Open this file using an SFTP client or file manager. Look for the line that defines $wp_version, for example: $wp_version = '6.9.4'; Compare this version number against the "Affected Versions" table above. If your site runs any version listed as affected and has not been updated to a patched version, it is vulnerable.
What an attacker actually does
An attacker exploits this vulnerability by sending a specially crafted request to the WordPress REST API batch endpoint, located at /wp-json/batch/v1. This endpoint is designed to process multiple API requests efficiently within a single call. The core of the attack relies on a "route confusion" flaw, identified as CVE-2026-63030. This bug occurs because the batch API performs validation of sub-requests in one step and then executes them in a separate step. A malformed sub-request within the batch can desynchronize these processes, causing WordPress to misinterpret subsequent requests.
This misinterpretation allows a request that was initially validated for a benign purpose to be dispatched to a different, unintended handler. This bypasses the normal permission checks and input sanitization that would otherwise apply to the target route. By leveraging this route confusion, an attacker can effectively elevate the privileges of their request or circumvent security filters.
The route confusion vulnerability is chained with a separate SQL injection vulnerability, CVE-2026-60137. This SQL injection flaw exists in how WordPress handles the author__not_in parameter within WP_Query database queries. When the route confusion bypasses input sanitization, an unauthenticated attacker can inject malicious SQL commands into this parameter. This chain of vulnerabilities allows the attacker to execute arbitrary code on the server. This can involve creating new administrative user accounts, uploading malicious files such as web shells, or directly manipulating the database to gain full control over the WordPress installation and potentially the underlying server environment. The attack does not require any prior authentication or user interaction.
How to detect a compromise
Detecting a compromise related to CVE-2026-63030 involves examining server logs and the WordPress installation for unusual activity. Attackers target the REST API batch endpoint, so specific indicators of compromise (IOCs) often appear in web server access logs.
Look for unusual activity in your web server access logs (e.g., Apache access.log, Nginx access.log), specifically POST requests targeting /wp-json/batch/v1 or ?rest_route=/batch/v1. Pay close attention to requests with complex or deeply nested JSON structures in the request body. Malicious logic is often hidden within these nested request arrays to evade simpler detection methods.
Examine server access logs for POST requests to these batch endpoints that result in unexpected file creations, modifications, or new user registrations. A successful exploitation might lead to the creation of new administrator accounts or the upload of malicious files.
Check for new, unauthorized administrator accounts within your WordPress installation. You can do this by logging into the WordPress admin area and navigating to "Users" to review the list of accounts. Alternatively, use WP-CLI if you have command-line access to your server: wp user list --field=user_login Investigate any unfamiliar or recently created accounts, especially those with administrator privileges.
Scan the file system for recently modified or newly created files in core WordPress directories, particularly .php files in wp-content/uploads/ or other unexpected locations. Attackers often place web shells or other malicious scripts in these directories to maintain access.
You can use command-line tools like grep to search web server access logs for the specific endpoint patterns. For example, for Apache logs: grep -E "/wp-json/batch/v1|\?rest_route=/batch/v1" /var/log/apache2/access.log (Adjust the log file path for your specific web server configuration, e.g., Nginx logs might be in /var/log/nginx/access.log).
Review database logs if available for unusual SQL queries, particularly those involving WP_Query with the author__not_in parameter, which is part of the chained SQL injection.
How to fix
To address CVE-2026-63030, apply the available security patches immediately.
Upgrade immediately to WordPress 6.9.5 if your site is running any version from 6.9.0 through 6.9.4.
Upgrade immediately to WordPress 7.0.2 if your site is running WordPress 7.0.0 or 7.0.1.
Upgrade immediately to WordPress 7.1 beta 2 if your site is running an earlier 7.1 beta release.
As a temporary mitigation, if immediate patching is not possible, block requests to the batch API endpoints
/wp-json/batch/v1or?rest_route=/batch/v1at a web application firewall (WAF) or server level. This can help prevent exploitation attempts.Consider disabling anonymous REST API access using a plugin if your site's functionality does not require it.
Timeline
Date | Event |
|---|---|
2026-07-17 | NVD record published |
2026-07-17 | Publicly disclosed |
2026-07-17 | Security patches released |
2026-07-21 | Added to CISA KEV |
2026-07-22 | NVD record last modified |
Sources
https://nvd.nist.gov/vuln/detail/CVE-2026-63030
https://www.wordfence.com/threat-intel/vulnerabilities/id/1ba55302-b38f-4932-bbba-cdd517380ad7
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/wordpress-core-69-701-remote-code-execution-via-rest-api-batch-request-route-confusion?asset_slug=wordpress
https://www.cve.org/CVERecord?id=CVE-2026-63030
https://patchstack.com/articles/ninety-minutes-watching-attackers-weaponize-the-wordpress-core-rce/
https://github.com/fullhunt/wp2shell-scan
https://nvd.nist.gov/vuln/detail/cve-2026-63030
https://patchstack.com/database/WordPress/WordPress/wordpress/vulnerability/wordpress-core-7-0-1-unauthenticated-remote-code-execution-vulnerability