Bottom line: CVE-2026-60137 and CVE-2026-63030 enable unauthenticated remote code execution on WordPress 6.9–7.0.1 without prerequisites when both vulnerabilities are combined.
WordPress contains two security vulnerabilities that, in combination, lead to unauthenticated code execution. Public exploits are already available; CERT.at recommends immediate updates to versions 6.8.6, 6.9.5, 7.0.2, or 7.1 Beta 2.
WordPress contains two distinct security vulnerabilities that in combination can lead to complete system compromise. The first vulnerability is a SQL injection (CVE-2026-60137) in the “author__not_in” parameter of the WP_Query function and affects WordPress versions from 6.8 onwards. According to the security advisory, this vulnerability alone carries only moderate risk.
Critical exploitability emerges from WordPress 6.9 onwards through a second vulnerability in the REST API (CVE-2026-63030, CVSS “Critical”), known as batch route confusion. This enables exploitation of the SQL injection to execute arbitrary code on the server (Remote Code Execution – RCE). According to Searchlight Cyber, this attack chain is applicable to standard installations without plugins and requires neither prior authentication nor special configurations. Multiple proof-of-concept exploits are already publicly available on GitHub, including the tool wp2shell, which significantly lowers the technical barrier to entry.
Affected versions are WordPress 6.8.0–6.8.5, 6.9.0–6.9.4, 7.0.0–7.0.1, and 7.1 Beta 1. WordPress.org has released patched versions (6.8.6, 6.9.5, 7.0.2, 7.1 Beta 2) and activated forced updates via the auto-update system. CERT.at recommends immediate patching.
Should immediate updates not be possible, Searchlight Cyber recommends the following interim measures: disable the REST API for unauthenticated users, block the path “/wp-json/batch/v1” and the query parameter “rest_route=/batch/v1” via web application firewall (both patterns must be blocked), or deploy a plugin to enforce authentication checks on batch requests. These measures may affect normal operation and are intended only as a temporary measure until updates are available.
Source: www.cert.at · Published July 20, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.