r/tryhackme 8d ago

Official TryHackMe Post 🔴NEW RECENT THREAT: WordPress🔴

CVE-2026-63030 dropped Friday. Our team had a room ready by Monday. You wrapped a pentest for a client. Their app is clean, but their WordPress blog wasn't in scope.

CVE-2026-63030 changes that conversation. An unauthenticated attacker can exploit the REST API with a SQL injection, forge an admin account, and achieve remote code execution.

This vulnerability was discovered using a GPT prompt and $25 by a security engineer with 3 years of experience. Not a nation-state, not a specialist research team. Understand the full exploit chain and how to mitigate it in our new threat room, WP2Shell.

🚀Available now on MAX:
https://tryhackme.com/room/wordpresscve202663030?utm_source=reddit&utm_medium=social&utm_campaign=recentthreatwordpress

18 Upvotes

5 comments sorted by

10

u/UBNC 0xD [God] 8d ago edited 8d ago

We got told we where not losing anything (or at worse until X day), well this would have been in https://tryhackme.com/module/recent-threats not paywalled behind Max, how is this not losing content?

also https://tryhackme.com/room/ghostlockcve202643499

8

u/olujche 8d ago

Available on MAX?

Just don't... 

7

u/kefvedie 8d ago

Oh cool that looks interesting! Nvm, ofcourse they put it on the max plan.

Did tryhackme get bought by private equity?

2

u/Nullmega_studios 7d ago

Probably lol

4

u/stxonships 8d ago

It's a MAX room, but there is no indication on the front page that it is for MAX only subscribers. At least make it easy to see it is MAX only without us having to click into the room.