A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution
ID: 6cebacc7-c205-5561-ad4b-87801b4bb284
STIX ID: report--6cebacc7-c205-5561-ad4b-87801b4bb284
Feed Name: CISecurity.org Advisories
A vulnerability chain in WordPress Core (CVE-2026-60137 and CVE-2026-63030) enables unauthenticated attackers to perform SQL injection via the author__not_in parameter combined with a REST API batch endpoint route confusion, potentially resulting in remote code execution on affected sites; successful exploitation could allow installation of programs, modification or deletion of data, or creation of privileged accounts depending on the compromised service account's rights.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
