- WordPress fixes two flaws: CVE-2026-60137 (SQL injection, medium severity) and CVE-2026-63030 (REST API batch route confusion, critical severity)
- When chained together, the bugs allowed remote execution of unauthenticated code, allowing for a complete takeover of the site.
- Administrators should urgently update to WordPress 6.9.5 or later to protect against widespread active attacks
Millions of WordPress websites could be at serious risk, researchers warn, due to two recently patched vulnerabilities that are actively being exploited in the wild.
WordPress developers released a patch for two vulnerabilities: a SQL injection bug tracked as CVE-2026-60137 and a REST API batch path confusion bug, tracked as CVE-2026-63030.
The first is a medium severity 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the second is a critical severity 9.8/10 vulnerability affecting WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2. most popular in the world. popular website builder.
Exploitation in progress
According The RegistryThese bugs are not that dangerous when analyzed separately, as they are quite difficult to exploit. However, when chained together, they allow unauthenticated threat actors to execute malicious code remotely, meaning they completely take over the website.
Knott security researchers say threat actors picked up on the scent fairly quickly.
The patch was released on Friday, but “in the early hours of Saturday morning, the successful exploit was already underway, initially using public exploit code to leak hashed credentials, and then remote code execution once additional details were made public,” Knott said.
“From our perspective across a global customer base, we are seeing the widespread impact of this vulnerability across organizations of all sizes and verticals.”
It is worth mentioning that these vulnerabilities affect WordPress directly, rather than different plugins or themes. WordPress is by far the most popular website building platform in the world, powering more than half of all websites that exist today.
To protect your assets, be sure to update WordPress to version 6.9.5 as it contains fixes for both flaws.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




