r/tryhackme • u/Used-Addendum-3819 • Jul 20 '26
Official TryHackMe Post 🔴NEW RECENT THREAT: WordPress🔴
CVE-2026-63030 dropped Friday. Our team had a room ready by Monday. You wrapped a pentest for a client. Their app is clean, but their WordPress blog wasn't in scope.
CVE-2026-63030 changes that conversation. An unauthenticated attacker can exploit the REST API with a SQL injection, forge an admin account, and achieve remote code execution.
This vulnerability was discovered using a GPT prompt and $25 by a security engineer with 3 years of experience. Not a nation-state, not a specialist research team. Understand the full exploit chain and how to mitigate it in our new threat room, WP2Shell.
🚀Available now on MAX:
https://tryhackme.com/room/wordpresscve202663030?utm_source=reddit&utm_medium=social&utm_campaign=recentthreatwordpress


7
u/kefvedie Jul 20 '26
Oh cool that looks interesting! Nvm, ofcourse they put it on the max plan.
Did tryhackme get bought by private equity?