Experts warn that millions of WordPress websites could be at risk following the revelation of worrying bugs.


  • WordPress fixes two vulnerabilities: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch route confusion, critical severity)
  • When chained together, the bugs allowed unauthenticated remote code execution, allowing complete takeover of the site.
  • Administrators should urgently upgrade to WordPress 6.9.5 or later to protect against widespread active attacks.

Millions of WordPress websites could be at serious risk, researchers warn, due to two recently patched vulnerabilities being actively exploited in the wild.

WordPress developers have released a patch for two vulnerabilities: a SQL injection bug tracked as CVE-2026-60137 and a REST API batch route confusion bug tracked as CVE-2026-63030.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top