Attackers pummel critical WordPress vuln to create all sorts of mischief
ID: a644f0d4-5d1c-5600-95d8-0d7764feb747
STIX ID: report--a644f0d4-5d1c-5600-95d8-0d7764feb747
Feed Name: The Register (Security)
WordPress patched two vulnerabilities—CVE-2026-63030 (critical REST API route confusion) and CVE-2026-60137 (moderate SQL injection)—that can be chained to allow unauthenticated RCE; public proof-of-concept code and AI-assisted reproduction led to rapid, widespread exploitation with tens of thousands of attempts, creation of backdoor admin accounts, fake malicious plugins, credential exfiltration, and deployment of additional tooling including the Overlord RAT. Administrators are urged to apply fixes immediately and inspect installations for new admin accounts, malicious plugins, or other indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
