CVE-2026-63030
Confirmed by 4 independent sources tracked by ThreatFilter. First reported 2026-07-17 22:23 UTC , most recent 2026-07-21 00:00 UTC.
Corroboration timeline
Each row is the first time that source reported this CVE, so the lag column shows how long each took relative to the earliest report. Independent corroboration is a confidence signal that a single advisory cannot give you.
- rapid7-blog 2026-07-17 22:23 UTC
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
- tenable-advisories 2026-07-20 13:36 UTC +3d
- sans-isc 2026-07-20 18:41 UTC +3d
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
- cisa-kev 2026-07-21 00:00 UTC +3d
CVE-2026-63030 — WordPress Core: WordPress Core Interpretation Conflict Vulnerability
How this page is built
ThreatFilter ingests 52 public threat-intelligence feeds. A page is published here only when at least 3 distinct sources report the same CVE — roughly 0.2% of the CVEs seen. Everything above is derived from those feeds; nothing is hand-written, and the timeline is the raw record of what each source published and when.
See the live advisory feed, the full source list, or the analyst tools.