Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs

Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs | Daily Reports Online

Share


  • WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)
  • When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover
  • Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks

Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.


WordPress developers released a patch for two vulnerabilities – an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.


Similar Posts