CVE-2026-63030 (wp2shell): One Bad REST Batch, One WordPress Shell
A CVSS 9.8 WordPress Core vulnerability chain lets unauthenticated attackers turn REST route confusion and SQL injection into remote code execution. Public PoCs are available, with early signs of in-the-wild activity reported.