- WordPress fixes two vulnerabilities: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch route confusion, critical severity)
- When chained together, the bugs allowed unauthenticated remote code execution, allowing complete takeover of the site.
- Administrators should urgently upgrade to WordPress 6.9.5 or later to protect against widespread active attacks.
Millions of WordPress websites could be at serious risk, researchers warn, due to two recently patched vulnerabilities being actively exploited in the wild.
WordPress developers have released a patch for two vulnerabilities: a SQL injection bug tracked as CVE-2026-60137 and a REST API batch route confusion bug tracked as CVE-2026-63030.
The first is a medium severity vulnerability, 5.9/10, affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5 and 7.0.x before 7.0.2, while the second is a critical severity flaw, 9.8/10, affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2, one of most important in the world. popular website builder.
Current operation
According to The registerThese bugs are not so dangerous when considered separately, as they are rather difficult to exploit. However, when chained together, they allow unauthenticated malicious actors to execute malicious code remotely, meaning a complete takeover of the website.
Knott security researchers say threat actors spotted the smell relatively quickly.
The patch was released Friday, but “by the early hours of Saturday morning, the successful exploit was already well underway, initially using public exploit code to exfiltrate hashed credentials, followed by remote code execution once additional details were made public,” Knott said.
“From our perspective of a global customer base, we see the widespread impact of this vulnerability across organizations of all sizes and across all industries. »
It is worth mentioning that these vulnerabilities directly affect WordPress, not different plugins or themes. WordPress is by far the most popular website building platform in the world, powering more than half of all websites in existence today.
To protect your assets, be sure to upgrade WordPress to version 6.9.5, as it contains fixes for both vulnerabilities.
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




