Knox CVE Database
/
CVE-2026-63030
High
7.5

CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

Added to the CISA KEV catalog:
July 21, 2026

Overview

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Vulnerability details

Affected vendor
WordPress
Affected product
Core
Weakness type (CWE)
CWE-436

CVE-2026-63030 is an interpretation conflict (CWE-436) in the WordPress REST API batch endpoint. The batch endpoint and the underlying routing layer disagree on how to parse route parameters, creating a gap where a crafted request is treated as valid by one layer while being routed differently by another. This conflict allows an attacker to reach the WP_Query layer with parameters that would ordinarily be blocked or sanitized at the routing stage, bypassing the normal route restrictions that govern which query arguments are accepted.


An attacker sends a crafted HTTP request to the REST API batch endpoint containing a manipulated route that exploits the interpretation conflict. This smuggles attacker-controlled author__not_in parameters into WP_Query, triggering the SQL injection flaw in CVE-2026-60137. Both vulnerabilities must be unpatched for the chain to succeed. The CVSS vector from NVD scores no integrity impact, but a secondary CNA assessment rates this critical with full integrity and availability impact, consistent with the Remote Code Execution outcome described in the advisory. The NVD vector should not be read as limiting the actual impact.

Severity and impact

7.5
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
None
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor web server and WordPress access logs for POST requests to the REST API batch endpoint (typically /wp-json/batch/v1) containing author__not_in parameters, which have no legitimate use in batch requests and indicate active exploitation of this chain.
  • Review database query logs for unexpected or malformed SQL fragments referencing author__not_in conditions originating from REST API sessions, particularly queries that do not correspond to any authenticated user session or recognized plugin workflow.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 24, 2026

Additional hardening

  • Restrict network access to the WordPress REST API batch endpoint at the WAF or reverse proxy layer for any installation that cannot immediately patch to 6.9.5 or 7.0.2.
  • Disable or rate-limit unauthenticated REST API access at the perimeter; the CVSS PR:N rating indicates no authentication is required to reach the vulnerable endpoint.
  • Deploy a WAF rule blocking requests to REST API routes that include author__not_in as a query parameter, as this parameter combination has no legitimate batch-request use case.
  • Isolate the WordPress database account to the minimum required privileges; restricting EXECUTE and FILE grants limits the post-SQL-injection RCE surface even if the injection itself succeeds.

Key dates

Published (NVD)
July 17, 2026
Added to CISA KEV
July 21, 2026
Remediation deadline
July 24, 2026
Last updated
July 22, 2026

References

Frequently asked questions

Does CVE-2026-63030 affect my FedRAMP authorization?

If WordPress Core runs inside your authorization boundary, yes. CVE-2026-63030 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of July 24, 2026. For a FedRAMP-authorized service, an unpatched KEV within your boundary is a finding — one you must either remediate or formally document a mitigation for before your assessor or sponsoring agency raises it during review.

How does Knox help me handle CVE-2026-63030?

Remediating WordPress Core is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. The patch is yours to apply; maintaining a defensible compliance posture while you apply it is not something you handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-63030. Exposure surfaces during ongoing monitoring rather than waiting until an assessor flags it at review time, giving your team earlier visibility and more time to act.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path to authorization: FedRAMP in 90 days for 90% less, without the delays or dependencies of a traditional build.

What happens if CVE-2026-63030 isn't remediated by July 24, 2026?

Missing the July 24, 2026 deadline turns CVE-2026-63030 into a POA&M item. A growing POA&M list can turn a routine continuous-monitoring review into a tough conversation with your sponsoring agency. Meeting the deadline keeps your authorization and agency relationship in good standing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting