Advisory

CVE-2026-63030 in WordPress

Known exploitedCVSS 9.8 (CVE record)Published Sep 30, 2026Last verified Oct 7, 2026

WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 have a remote code execution flaw in the REST API batch route that is being exploited. Update to 6.9.5 or 7.0.2.

Exploited in the wild
Yes (CISA KEV)
Installs not updated
Unknown
Affected and fixed versions
ComponentAffectedFixed in
WordPress (core)6.9 up to (not including) 6.9.5, 7.0 up to (not including) 7.0.26.9.5, 7.0.2
Run a free scan of your site

The free scan checks what is visible from outside your site. It does not log in, and it cannot confirm on its own whether this specific issue is present.

Summary

This is a Remote Code Execution (RCE) vulnerability, CVE-2026-63030, affecting WordPress Core. It impacts WordPress Core versions 6.9.x, 7.0.x, and 7.1 beta releases earlier than 7.1 beta 2. Patches are available in WordPress 6.9.5, 7.0.2, and 7.1 beta 2. The vulnerability is known to be actively exploited in the wild, with public proof-of-concept exploits available.

Affected and patched versions

Affected Versions

Patched Versions

WordPress Core 6.9.0 through 6.9.4

WordPress Core 6.9.5

WordPress Core 7.0.0 through 7.0.1

WordPress Core 7.0.2

WordPress Core 7.1 beta releases earlier than 7.1 beta 2

WordPress Core 7.1 beta 2

Is my site vulnerable?

To determine if your WordPress site is vulnerable, check its installed version. You can find this information in a few ways.

The most straightforward method is to log into your WordPress administration area. Navigate to the "Dashboard" and then look for the "At a Glance" widget, which often displays your WordPress version. Alternatively, go to "Updates" in the left-hand menu; the current version is typically shown there.

If you cannot access the administration area, you can check the wp-includes/version.php file in your WordPress installation directory. Open this file using an SFTP client or file manager. Look for the line that defines $wp_version, for example: $wp_version = '6.9.4'; Compare this version number against the "Affected Versions" table above. If your site runs any version listed as affected and has not been updated to a patched version, it is vulnerable.

What an attacker actually does

An attacker exploits this vulnerability by sending a specially crafted request to the WordPress REST API batch endpoint, located at /wp-json/batch/v1. This endpoint is designed to process multiple API requests efficiently within a single call. The core of the attack relies on a "route confusion" flaw, identified as CVE-2026-63030. This bug occurs because the batch API performs validation of sub-requests in one step and then executes them in a separate step. A malformed sub-request within the batch can desynchronize these processes, causing WordPress to misinterpret subsequent requests.

This misinterpretation allows a request that was initially validated for a benign purpose to be dispatched to a different, unintended handler. This bypasses the normal permission checks and input sanitization that would otherwise apply to the target route. By leveraging this route confusion, an attacker can effectively elevate the privileges of their request or circumvent security filters.

The route confusion vulnerability is chained with a separate SQL injection vulnerability, CVE-2026-60137. This SQL injection flaw exists in how WordPress handles the author__not_in parameter within WP_Query database queries. When the route confusion bypasses input sanitization, an unauthenticated attacker can inject malicious SQL commands into this parameter. This chain of vulnerabilities allows the attacker to execute arbitrary code on the server. This can involve creating new administrative user accounts, uploading malicious files such as web shells, or directly manipulating the database to gain full control over the WordPress installation and potentially the underlying server environment. The attack does not require any prior authentication or user interaction.

How to detect a compromise

Detecting a compromise related to CVE-2026-63030 involves examining server logs and the WordPress installation for unusual activity. Attackers target the REST API batch endpoint, so specific indicators of compromise (IOCs) often appear in web server access logs.

Look for unusual activity in your web server access logs (e.g., Apache access.log, Nginx access.log), specifically POST requests targeting /wp-json/batch/v1 or ?rest_route=/batch/v1. Pay close attention to requests with complex or deeply nested JSON structures in the request body. Malicious logic is often hidden within these nested request arrays to evade simpler detection methods.

Examine server access logs for POST requests to these batch endpoints that result in unexpected file creations, modifications, or new user registrations. A successful exploitation might lead to the creation of new administrator accounts or the upload of malicious files.

Check for new, unauthorized administrator accounts within your WordPress installation. You can do this by logging into the WordPress admin area and navigating to "Users" to review the list of accounts. Alternatively, use WP-CLI if you have command-line access to your server: wp user list --field=user_login Investigate any unfamiliar or recently created accounts, especially those with administrator privileges.

Scan the file system for recently modified or newly created files in core WordPress directories, particularly .php files in wp-content/uploads/ or other unexpected locations. Attackers often place web shells or other malicious scripts in these directories to maintain access.

You can use command-line tools like grep to search web server access logs for the specific endpoint patterns. For example, for Apache logs: grep -E "/wp-json/batch/v1|\?rest_route=/batch/v1" /var/log/apache2/access.log (Adjust the log file path for your specific web server configuration, e.g., Nginx logs might be in /var/log/nginx/access.log).

Review database logs if available for unusual SQL queries, particularly those involving WP_Query with the author__not_in parameter, which is part of the chained SQL injection.

How to fix

To address CVE-2026-63030, apply the available security patches immediately.

  1. Upgrade immediately to WordPress 6.9.5 if your site is running any version from 6.9.0 through 6.9.4.

  2. Upgrade immediately to WordPress 7.0.2 if your site is running WordPress 7.0.0 or 7.0.1.

  3. Upgrade immediately to WordPress 7.1 beta 2 if your site is running an earlier 7.1 beta release.

  4. As a temporary mitigation, if immediate patching is not possible, block requests to the batch API endpoints /wp-json/batch/v1 or ?rest_route=/batch/v1 at a web application firewall (WAF) or server level. This can help prevent exploitation attempts.

  5. Consider disabling anonymous REST API access using a plugin if your site's functionality does not require it.

Timeline

Date

Event

2026-07-17

NVD record published

2026-07-17

Publicly disclosed

2026-07-17

Security patches released

2026-07-21

Added to CISA KEV

2026-07-22

NVD record last modified

Sources

  • https://nvd.nist.gov/vuln/detail/CVE-2026-63030

  • https://www.wordfence.com/threat-intel/vulnerabilities/id/1ba55302-b38f-4932-bbba-cdd517380ad7

  • https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/wordpress-core-69-701-remote-code-execution-via-rest-api-batch-request-route-confusion?asset_slug=wordpress

  • https://www.cve.org/CVERecord?id=CVE-2026-63030

  • https://patchstack.com/articles/ninety-minutes-watching-attackers-weaponize-the-wordpress-core-rce/

  • https://github.com/fullhunt/wp2shell-scan

  • https://nvd.nist.gov/vuln/detail/cve-2026-63030

  • https://patchstack.com/database/WordPress/WordPress/wordpress/vulnerability/wordpress-core-7-0-1-unauthenticated-remote-code-execution-vulnerability

PowerSEC coverage
PowerSEC detects the affected versions on every plan, and has since September 28, 2026. No PowerSEC firewall rule blocks this attack. Update to 6.9.5 or 7.0.2 (or a later release on the same branch) to remove the vulnerability.
This record contains material that is subject to copyright Copyright 2012-2026 Defiant Inc. Copyright 1999-2026 The MITRE Corporation
Hacked? Talk to us
CVE-2026-63030 in WordPress | PowerSEC