- WordPress fixes two bugs: CVE-2026-60137 (SQL Injection, Medium Severity) and CVE-2026-63030 (REST API Batch Route Confusion, Critical Severity)
- Once chained, the flaws enabled unauthorized remote code execution, allowing full site takeover
- Administrators should immediately upgrade to WordPress 6.9.5 or later to protect against widespread active attacks
Millions of WordPress websites could be at serious risk, researchers warn, due to two recently patched vulnerabilities that are being actively exploited in the wild.
WordPress developers released a patch for two vulnerabilities – an SQL injection flaw tracked as CVE-2026-60137 and a REST API batch route confusion flaw tracked as CVE-2026-63030.
The former is a medium severity, 5.9/10 vulnerability that affects WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical severity, 9.8/10 bug that affects versions 6.9.05 before and 7.9.05 before and 7.9.0. of the world’s most popular website builder.
Exploitation in progress
According to The registerthese bugs are not that dangerous when viewed separately as they are quite difficult to exploit. However, when linked together, they allow unauthorized threat actors to execute malicious code remotely, meaning full takeover of the website.
Security researchers at Knott say threat actors picked up the scent pretty quickly.
The patch was released on Friday, but “by the early hours of Saturday morning, the successful exploit was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following as further details were released,” Knott said.
“From our vantage point across a global customer base, we see a widespread impact of this vulnerability across organizations of every size and every vertical.”
It’s worth mentioning that these vulnerabilities affect WordPress directly, rather than different plugins or themes. WordPress is by far the most popular website building platform in the world, powering more than half of all websites in existence today.
To protect your assets, be sure to upgrade WordPress to version 6.9.5 as it contains fixes for both bugs.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



