T
Threats
WordPress Core Critical and High Severity Vulnerabilities
Overview
CVE: CVE-2026-60137, CVE-2026-63030
Severity: Critical
Date: 22 July 2026
Affected Versions
WordPress 6.8.x (up to 6.8.5): affected by CVE-2026-63030 only, fixed in 6.8.6.
WordPress 6.9.x (up to 6.9.4): affected by both vulnerabilities, fixed in 6.9.5.
WordPress 7.0.x (up to 7.0.1): affected by both vulnerabilities, fixed in 7.0.2.
WordPress 7.1 beta: affected by both vulnerabilities, fixed in 7.1 beta 2.
Versions prior to 6.8 are not affected.
Vulnerability Breakdown
CVE-2026-60137 - REST API route confusion leading to remote code execution
Severity: Critical
CVSS: 9.1
Description: A batch-route confusion issue in the WordPress REST API allows a malicious request to be misrouted, leading to remote code execution.
Impact: Unauthenticated remote code execution on the affected site.
Conditions: No authentication required. Public proof of concept code is circulating, and exploitation attempts have been observed within hours of disclosure.
Notes: Chains with CVE-2026-63030 to form the full exploitation path on WordPress 6.9.x, 7.0.x, and the 7.1 beta.
CVE-2026-63030 - SQL injection in the WP_Query author__not_in parameter
Severity: High
CVSS: Rated High by the WordPress security team
Description: A facilitated SQL injection vulnerability exists in the author__not_in parameter of WP_Query.
Impact: Unauthorised database access, and full remote code execution when chained with CVE-2026-60137.
Conditions: No authentication required.
Notes: Present in WordPress 6.8.x and later. Only this issue affects 6.8.x, while 6.9.x, 7.0.x, and the 7.1 beta are affected by both issues in the chain.
Mitigation
Update WordPress core to 7.0.2, 6.9.5, or 6.8.6 immediately, depending on your current release line.
Enable automatic background updates so future security releases apply without delay.
If immediate updating is not possible, engage your hosting provider or SOC to confirm interim WAF protections are active.
Verify the update by checking your WordPress version under Dashboard > At a Glance.
Review server and access logs for signs of exploitation, including unexpected REST API requests and unusual database queries.
Summary for IT Teams
Products: WordPress Core (self-hosted, version 6.8 and later)
Threat Level: Critical, CVSS 9.1
Action Required: Patch to WordPress 7.0.2, 6.9.5, or 6.8.6 immediately. Confirm automatic updates are enabled and review logs for signs of exploitation.
Reference
Need Help?
If your organisation needs assistance assessing or patching WordPress, the Secure ISS SOC team is ready to help. Call 1300 769 460 or get in touch online.

