3:49PM, 20 July 2026
TLP Rating:
CVE-2026-63030 and CVE-2026-60137 affecting WordPress
Two vulnerabilities affecting WordPress are under active exploitation.
CVE-2026-63030 is a route confusion flaw in a WordPress REST API batch endpoint, and CVE-2026-60137 is caused by improper sanitisation in WP_Query.
What's happening
Systems affected
These vulnerabilities affect the following products:
- WordPress 6.9.0 through 6.9.4
- WordPress 7.0.0 through 7.0.1
- WordPress 7.1 beta release
NOTE: when CVE-2026-60137 is exploited in isolation, WordPress versions 6.8.0 - 6.8.5 are vulnerable to an SQL injection issue only.
What this means
An unauthenticated attacker could chain these vulnerabilities together to perform SQL injection leading to remote code execution.
What to do
Prevention
The NCSC encourages organisations in New Zealand that use the affected products to review the vendor advisory External Link External Link and apply the remediations as soon as possible.
More information
Read more about this alert on the vendor website:
WordPress 7.0.2 Release – WordPress News External Link
If you require more information or further support, submit a report on our website: