Feed/CVE-2026-6303
CVE-2026-6303HIGHCVSS 8.8

CVE-2026-6303

Published Apr 15, 2026·Updated Jun 17, 2026

NVD Description

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Public Exploits & PoCs10 found

[POC] CVE-2026-63030 — wp2shell

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

7

[POC] CVE-2026-63030 — wp2shell-lab

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

4

[POC] CVE-2026-63030 — wp2shell-poc

WordPress REST API SQLi to RCE (CVE-2026-63030)

4

[POC] CVE-2026-63030 — wp2shell-poc

CVE-2026-63030

4

[POC] CVE-2026-63030 — wp2shell

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.

3

[POC] CVE-2026-63030 — wp2shell-lab

Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1

2

[POC] CVE-2026-63030 — wp2shell-detect

Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.

1

[POC] CVE-2026-63030 — wp2shell

wp2shell - WordPress RCE & PoC (CVE-2026-63030 + CVE-2026-60137)

1

[POC] CVE-2026-63030 — sxwp2shell

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

1

[POC] CVE-2026-63030 — CVE-2026-63030

Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).

1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free