CVE-2026-63030 and CVE-2026-60137 affecting WordPress

This section contains time sensitive announcements about specific cyber threats, vulnerabilities and scams. Each alert has information you need to be aware of, and what actions to take to mitigate any risk to you or your organisation.

Subscribe to our updates to be notified as soon as we publish an alert.

3:49PM, 20 July 2026

TLP Rating: Clear

CVE-2026-63030 and CVE-2026-60137 affecting WordPress

Two vulnerabilities affecting WordPress are under active exploitation. 

CVE-2026-63030 is a route confusion flaw in a WordPress REST API batch endpoint, and CVE-2026-60137 is caused by improper sanitisation in WP_Query.

What's happening

Systems affected

These vulnerabilities affect the following products: 

  • WordPress 6.9.0 through 6.9.4
  • WordPress 7.0.0 through 7.0.1
  • WordPress 7.1 beta release

NOTE: when CVE-2026-60137 is exploited in isolation, WordPress versions 6.8.0 - 6.8.5 are vulnerable to an SQL injection issue only. 

What this means

An unauthenticated attacker could chain these vulnerabilities together to perform SQL injection leading to remote code execution.

What to do

Prevention

The NCSC encourages organisations in New Zealand that use the affected products to review the vendor advisory External Link  External Link and apply the remediations as soon as possible.

More information

Read more about this alert on the vendor website:

WordPress 7.0.2 Release – WordPress News External Link

If you require more information or further support, submit a report on our website:

Report an incident