HackMyIP
← Back to News
2026-07-20 The Hacker News

WordPress RCE Chain and SonicWall Zero-Days Hit This Week

Zero-DayVulnerabilityAI Threats

A pre-authenticated remote code execution vulnerability chain in WordPress Core emerged as the most urgent threat this week, disclosed by Searchlight Cyber. The flaw combines CVE-2026-63030, a REST API batch-route confusion bug, with CVE-2026-60137, a SQL injection in WordPress core. When chained, the two allow anonymous attackers to achieve code execution on a standard WordPress installation without plugins or special conditions. watchTowr confirmed that proof-of-concept exploits are already circulating and reported the first signs of in-the-wild exploitation. CEO Benjamin Harris warned that with WordPress running on hundreds of millions of websites globally, unpatched instances will be the primary target. Defenders should apply patches immediately and audit for backdoors that may have already been planted. Security teams can use a port scanner to verify exposed admin interfaces and a SSL/TLS checker to confirm transport-layer protections on WordPress hosting environments.

In parallel, Volexity attributed exploitation of SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days to a previously undocumented threat actor tracked as UTA0533. The activity began on June 22, 2026, weeks before public disclosure, and was uncovered during an incident response investigation earlier this month. The actor deployed multiple zero-day exploits including CVE-2026-15409, custom malware tailored for SonicWall SMA appliances, and additional tradecraft. Organizations running SonicWall SMA 1000 series devices should review logs for indicators of compromise dating back to late June and apply patches as soon as they become available. To verify whether your VPN endpoints are leaking traffic or being misrouted, run a VPN/proxy detector against your public-facing infrastructure.

The week's disclosures reflect a broader shift in the threat landscape: AI-assisted vulnerability research tooling is accelerating the pace at which bugs are discovered and weaponized. Searchlight explicitly identified the WordPress Core RCE as the latest example of how the same technology used by defenders to find flaws is being abused by attackers to turn them into exploits. A SharePoint zero-day and continued attacks against AI services rounded out the headlines, reinforcing that defenders are no longer operating on a level playing field. As PoC code moves from private channels into public circulation within hours of disclosure, organizations must compress patch cycles and deploy continuous monitoring for post-exploitation activity. Start with a privacy checkup to baseline your attack surface and prioritize remediation.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →