Experts caution that a significant number of WordPress sites may be in danger due to the discovery of concerning vulnerabilities

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Critical Vulnerabilities Addressed in WordPress Update

  • WordPress has issued patches for two significant vulnerabilities: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch-route confusion, critical severity).
  • When exploited in tandem, these vulnerabilities can facilitate unauthenticated remote code execution, jeopardizing entire websites.
  • Administrators are strongly advised to update to WordPress version 6.9.5 or later to safeguard against ongoing widespread attacks.

Recent research indicates that millions of WordPress sites may be vulnerable, with the two newly patched flaws currently subject to active exploitation.

The vulnerabilities addressed include an SQL injection flaw (CVE-2026-60137) rated at medium severity and a critical REST API batch-route confusion flaw (CVE-2026-63030).

The SQL injection issue, rated 5.9/10 in severity, is present in WordPress versions 6.8.x prior to 6.8.6, 6.9.x before 6.9.5, and 7.0.x leading up to 7.0.2.

In contrast, the critical severity flaw, rated at 9.8/10, affects versions 6.9.x before 6.9.5 and 7.0.x prior to 7.0.2 of the globally preeminent website creation platform.

Exploitation in Progress

As reported by The Register, the individual vulnerabilities are somewhat esoteric when isolated, thus complicating exploitation.

Yet, when combined, they enable unauthorized actors to execute malicious code remotely—a scenario that could lead to complete control over affected websites.

Security experts at Knott disclosed that the vulnerabilities were rapidly recognized and exploited by malicious entities.

The initial patch surfaced on Friday, but by the early hours of Saturday, successful exploitation was already rampant; initial attacks leveraged publicly available exploit code to extract hashed credentials, followed by remote code execution once additional information became accessible, Knott noted.

The firm illustrated widespread repercussions of this vulnerability affecting diverse organizations across multiple sectors.

It is imperative to note that these security weaknesses directly compromise WordPress itself, rather than its plugins or themes.

Given that WordPress accounts for over half of all websites globally, the urgency of this situation is underscored.

Person wearing a WordPress t-shirt typing on a keyboard at a desk with a computer monitor and a WordPress-themed mug.

To mitigate risk, it is essential that users upgrade to WordPress version 6.9.5, which effectively rectifies both vulnerabilities.

Source link: Techradar.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading