View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

WordPress Core Pre-Auth RCE CVE-2026-63030 Affects Versions 6.9.0

๐Ÿšจ ACTIVE EXPLOITATION

  • WordPress Core Pre-Auth RCE Vulnerability CVE-2026-63030 Affects Versions 6.9.0 to 7.0.1 โ€” fullhunt.io
    A pre-authentication remote code execution vulnerability was found in WordPress Core versions 6.9.0 through 7.0.1.
    • Applies to WordPress Core versions 6.9.0 through 7.0.1, patched in 6.9.5 and 7.0.2
    • Vulnerability involves a pre-auth SQL injection via the REST API batch endpoint allowing remote code execution
    • Attack exploits array index desynchronization in batch request processing to bypass parameter validation
    • Re-entrancy bug allows nested REST API calls without proper dispatch guards, exploitable without persistent object cache
    • Fixes include synchronizing arrays in request validation and adding dispatch guards to prevent nested calls
      ๐Ÿ“Ž Coverage: fullhunt.io ยท ๐Ÿ‘ via r/netsec

๐Ÿ”“ CVEs & KEV

  • CVE-2026-12228 โ€” CVSS 8.7 โ€” Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms
    A stored cross-site scripting vulnerability affecting direct messages in the parisneo/lollms project.

  • CVE-2026-16154 โ€” CVSS 7.3 โ€” SourceCodester Class and Exam Timetabling System edit_room1.php SQL injection
    SQL injection vulnerability in edit_room1.php of SourceCodester Class and Exam Timetabling System.

  • CVE-2026-16152 โ€” CVSS 7.3 โ€” SourceCodester Class and Exam Timetabling System edit_rooma.php SQL injection
    SQL injection vulnerability in edit_rooma.php of SourceCodester Class and Exam Timetabling System.

  • CVE-2026-16151 โ€” CVSS 6.3 โ€” CartoDB carto-api-client filters.ts addFilter prototype pollution
    Prototype pollution vulnerability in addFilter function of CartoDB carto-api-client filters.ts.

  • CVE-2026-57857 โ€” CVSS 4.3 โ€” Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_me parameter
    Reflected cross-site scripting vulnerability in Flow Payment Plugin for WordPress via error_me parameter.

  • CVE-2026-16155 โ€” CVSS 3.5 โ€” SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting
    Cross-site scripting vulnerability in schoolyr.php of SourceCodester Class and Exam Timetabling System.

  • CVE-2026-16194 โ€” CVSS โ€” zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery
    Server-side request forgery vulnerability in WebFetch.execute of zhayujie CowAgent web_fetch.py.

  • CVE-2026-16156 โ€” CVSS โ€” SourceCodester Class and Exam Timetabling System forexam.php cross site scripting
    Cross-site scripting vulnerability in forexam.php of SourceCodester Class and Exam Timetabling System.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check