A critical SQL injection vulnerability, designated as CVE-2026-63030, has been discovered in WordPress Core, enabling unauthenticated remote code execution. This vulnerability, dubbed "wp2shell", was initially disclosed without a CVE number but has since been assigned one, highlighting its severity. Exploitation of this flaw began shortly after its announcement, underscoring the need for prompt action. The fact that this vulnerability affects WordPress Core, rather than a plugin, makes it particularly noteworthy, as Core vulnerabilities are less common and can have broader implications. Users running WordPress are advised to immediately assess their exposure to this vulnerability1. The active exploitation of CVE-2026-63030 expands the attack surface, making it essential for practitioners to prioritize mitigation based on their specific exposure and evidence of exploitation, so what matters most is taking swift action to patch or mitigate this vulnerability to prevent potential breaches.