Critical RCE and SQL Injection Vulnerabilities in WordPress Disclosed
ID: 23475917-e697-57b3-b7b2-2b83474d35aa
STIX ID: report--23475917-e697-57b3-b7b2-2b83474d35aa
Feed Name: ThreatCluster
On July 17, 2026 WordPress disclosed two critical, unauthenticated vulnerabilities — CVE-2026-63030 (RCE in the REST API) and CVE-2026-60137 (SQL injection) — affecting default installations; WordPress released patches in 7.0.2 (with forced updates enabled) and Cloudflare deployed WAF protections for customers. Organizations are advised to apply patches immediately or implement WAF rules; there are no confirmed in-the-wild exploits yet, but the risk remains due to potential reverse engineering of the patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
