Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs



  • WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)
  • When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover
  • Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks

Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.

WordPress developers released a patch for two vulnerabilities – an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.

https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img