Experts are warning that millions of WordPress websites could be at risk following the revelation of worrying bugs


  • WordPress fixes two bugs: CVE-2026-60137 (SQL Injection, Medium Severity) and CVE-2026-63030 (REST API Batch Route Confusion, Critical Severity)
  • Once chained, the flaws enabled unauthorized remote code execution, allowing full site takeover
  • Administrators should immediately upgrade to WordPress 6.9.5 or later to protect against widespread active attacks

Millions of WordPress websites could be at serious risk, researchers warn, due to two recently patched vulnerabilities that are being actively exploited in the wild.

WordPress developers released a patch for two vulnerabilities – an SQL injection flaw tracked as CVE-2026-60137 and a REST API batch route confusion flaw tracked as CVE-2026-63030.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top