Status: KEV
| Advisory ID: CVE-2026-63030
Key Details
| CVE | CVE-2026-63030 |
| Vulnerability Name | WordPress Core Interpretation Conflict Vulnerability |
| Affected products | WordPress Core |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-436 (Interpretation Conflict) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-07-21. |
| Exploitation prediction (EPSS) | 10.12% probability of exploitation in the next 30 days (95% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-07-24 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
What to Do
Monitor WordPress's web page for any future patch releases.
References
KEV Required Action