THIS article addresses critical vulnerabilities in WordPress identified as CVE-2026-60137 and CVE-2026-63030, responsible for unauthenticated remote code execution (RCE). The CVSS score for CVE-2026-63030 is notably high at 9.8, indicating a severe security risk. Attackers can exploit these vulnerabilities through public-facing installations of WordPress, allowing code execution without requiring authentication. Affected versions include WordPress Core 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
The article recommends immediate updates to versions 6.8.6, 6.9.5, or 7.0.2 to mitigate risks. It also describes the attack methodology involving SQL injection and REST API exploitation, warns of active exploitation in the wild, and advises users to monitor logs for signs of compromise.