PT-2026-60856 · WordPress · Wordpress

CVE-2026-63030

·

Published

2026-07-17

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress versions 6.9.x through 6.9.4 WordPress versions 7.0.x through 7.0.1
Description A REST API batch endpoint route confusion issue exists which, when combined with the author not in WP Query SQL Injection, allows an attacker to perform SQL Injection and achieve Remote Code Execution.
Recommendations Update WordPress versions 6.9.x to 6.9.5. Update WordPress versions 7.0.x to 7.0.2.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63030

Affected Products

Wordpress