securityonline.info 7/21/2026, 3:32:54 AM · external

Critical WordPress Bug Lets Attackers Run Code Remotely

Critical WordPress Bug Lets Attackers Run Code Remotely
Developing story malware 10 articles tracked
WordPress core flaws CVE-2026-60137 and CVE-2026-63030 exploited in the wild
CyberSIXT Evidence Panel
Primary Source wiz.io
CISA KEV Not in KEV
Patch Patch Status Unknown

THIS article addresses critical vulnerabilities in WordPress identified as CVE-2026-60137 and CVE-2026-63030, responsible for unauthenticated remote code execution (RCE). The CVSS score for CVE-2026-63030 is notably high at 9.8, indicating a severe security risk. Attackers can exploit these vulnerabilities through public-facing installations of WordPress, allowing code execution without requiring authentication. Affected versions include WordPress Core 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.

The article recommends immediate updates to versions 6.8.6, 6.9.5, or 7.0.2 to mitigate risks. It also describes the attack methodology involving SQL injection and REST API exploitation, warns of active exploitation in the wild, and advises users to monitor logs for signs of compromise.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline