Attackers are actively exploiting a critical WordPress vulnerability, chaining two bugs to achieve pre-authentication remote code execution. This exploit is particularly concerning, as it allows attackers to execute arbitrary code without authentication, potentially leading to widespread mischief. The vulnerabilities, including CVE-2026-63030, were publicly disclosed and quickly reproduced using advanced AI models, demonstrating the accelerated pace of exploitation. Security researchers warn that the use of AI assistance in reproducing these vulnerabilities is likely, given the ease of reproduction. The disclosure of CVE-2026-63030 has expanded the active attack surface, making it essential for users to prioritize patching based on their exposure and exploitation evidence. This vulnerability matters to practitioners because it highlights the need for swift action in securing WordPress installations to prevent exploitation, as attackers are already leveraging these vulnerabilities to create significant security threats1.