Experts warn millions of WordPress websites could be at risk after worrying bugs revealed



  • WordPress fixes two flaws: CVE-2026-60137 (SQL injection, medium severity) and CVE-2026-63030 (REST API batch route confusion, critical severity)
  • When chained together, the bugs allowed remote execution of unauthenticated code, allowing for a complete takeover of the site.
  • Administrators should urgently update to WordPress 6.9.5 or later to protect against widespread active attacks

Millions of WordPress websites could be at serious risk, researchers warn, due to two recently patched vulnerabilities that are actively being exploited in the wild.

WordPress developers released a patch for two vulnerabilities: a SQL injection bug tracked as CVE-2026-60137 and a REST API batch path confusion bug, tracked as CVE-2026-63030.

Leave a Comment

Your email address will not be published. Required fields are marked *