logo

A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution

ID: 6cebacc7-c205-5561-ad4b-87801b4bb284

STIX ID: report--6cebacc7-c205-5561-ad4b-87801b4bb284

Feed Name: CISecurity.org Advisories

Threat Score
80/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

A vulnerability chain in WordPress Core (CVE-2026-60137 and CVE-2026-63030) enables unauthenticated attackers to perform SQL injection via the author__not_in parameter combined with a REST API batch endpoint route confusion, potentially resulting in remote code execution on affected sites; successful exploitation could allow installation of programs, modification or deletion of data, or creation of privileged accounts depending on the compromised service account's rights.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.