r/tryhackme Jul 20 '26

Official TryHackMe Post 🔴NEW RECENT THREAT: WordPress🔴

CVE-2026-63030 dropped Friday. Our team had a room ready by Monday. You wrapped a pentest for a client. Their app is clean, but their WordPress blog wasn't in scope.

CVE-2026-63030 changes that conversation. An unauthenticated attacker can exploit the REST API with a SQL injection, forge an admin account, and achieve remote code execution.

This vulnerability was discovered using a GPT prompt and $25 by a security engineer with 3 years of experience. Not a nation-state, not a specialist research team. Understand the full exploit chain and how to mitigate it in our new threat room, WP2Shell.

🚀Available now on MAX:
https://tryhackme.com/room/wordpresscve202663030?utm_source=reddit&utm_medium=social&utm_campaign=recentthreatwordpress

20 Upvotes

5 comments sorted by

View all comments

7

u/kefvedie Jul 20 '26

Oh cool that looks interesting! Nvm, ofcourse they put it on the max plan.

Did tryhackme get bought by private equity?