NEW: Group Profiler — instant APT intel lookup. Try it →

← all advisories

CVE-2026-63030

Confirmed by 4 independent sources tracked by ThreatFilter. First reported 2026-07-17 22:23 UTC , most recent 2026-07-21 00:00 UTC.

HIGH 7.5 CISA KEV EXPLOITED wordpress

Corroboration timeline

Each row is the first time that source reported this CVE, so the lag column shows how long each took relative to the earliest report. Independent corroboration is a confidence signal that a single advisory cannot give you.

  1. rapid7-blog 2026-07-17 22:23 UTC

    CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

  2. tenable-advisories 2026-07-20 13:36 UTC +3d

    wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

  3. sans-isc 2026-07-20 18:41 UTC +3d

    WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

  4. cisa-kev 2026-07-21 00:00 UTC +3d

    CVE-2026-63030 — WordPress Core: WordPress Core Interpretation Conflict Vulnerability

How this page is built

ThreatFilter ingests 52 public threat-intelligence feeds. A page is published here only when at least 3 distinct sources report the same CVE — roughly 0.2% of the CVEs seen. Everything above is derived from those feeds; nothing is hand-written, and the timeline is the raw record of what each source published and when.

See the live advisory feed, the full source list, or the analyst tools.