T

Threats

WordPress Core Critical and High Severity Vulnerabilities

Overview

  • CVE: CVE-2026-60137, CVE-2026-63030

  • Severity: Critical

  • Date: 22 July 2026


Affected Versions

  • WordPress 6.8.x (up to 6.8.5): affected by CVE-2026-63030 only, fixed in 6.8.6.

  • WordPress 6.9.x (up to 6.9.4): affected by both vulnerabilities, fixed in 6.9.5.

  • WordPress 7.0.x (up to 7.0.1): affected by both vulnerabilities, fixed in 7.0.2.

  • WordPress 7.1 beta: affected by both vulnerabilities, fixed in 7.1 beta 2.

  • Versions prior to 6.8 are not affected.


Vulnerability Breakdown

CVE-2026-60137 - REST API route confusion leading to remote code execution

  • Severity: Critical

  • CVSS: 9.1

  • Description: A batch-route confusion issue in the WordPress REST API allows a malicious request to be misrouted, leading to remote code execution.

  • Impact: Unauthenticated remote code execution on the affected site.

  • Conditions: No authentication required. Public proof of concept code is circulating, and exploitation attempts have been observed within hours of disclosure.

  • Notes: Chains with CVE-2026-63030 to form the full exploitation path on WordPress 6.9.x, 7.0.x, and the 7.1 beta.


CVE-2026-63030 - SQL injection in the WP_Query author__not_in parameter

  • Severity: High

  • CVSS: Rated High by the WordPress security team

  • Description: A facilitated SQL injection vulnerability exists in the author__not_in parameter of WP_Query.

  • Impact: Unauthorised database access, and full remote code execution when chained with CVE-2026-60137.

  • Conditions: No authentication required.

  • Notes: Present in WordPress 6.8.x and later. Only this issue affects 6.8.x, while 6.9.x, 7.0.x, and the 7.1 beta are affected by both issues in the chain.


Mitigation

  • Update WordPress core to 7.0.2, 6.9.5, or 6.8.6 immediately, depending on your current release line.

  • Enable automatic background updates so future security releases apply without delay.

  • If immediate updating is not possible, engage your hosting provider or SOC to confirm interim WAF protections are active.

  • Verify the update by checking your WordPress version under Dashboard > At a Glance.

  • Review server and access logs for signs of exploitation, including unexpected REST API requests and unusual database queries.


Summary for IT Teams

  • Products: WordPress Core (self-hosted, version 6.8 and later)

  • Threat Level: Critical, CVSS 9.1

  • Action Required: Patch to WordPress 7.0.2, 6.9.5, or 6.8.6 immediately. Confirm automatic updates are enabled and review logs for signs of exploitation.


Reference


Need Help?

If your organisation needs assistance assessing or patching WordPress, the Secure ISS SOC team is ready to help. Call 1300 769 460 or get in touch online.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.