WordPress 6.8 to 7.0: Critical Unauthenticated RCE Chain20. July 2026CybersecurityCVE-2026-60137 and CVE-2026-63030 enable unauthenticated remote code execution on WordPress 6.9–7.0.1 without prerequisites when both vulnerabilities are combined. Share on: