Two new high severity WordPress vulnerabilities, patch immediately!
ID: e8f0f445-6268-53d1-b879-01fe71d7ceff
STIX ID: report--e8f0f445-6268-53d1-b879-01fe71d7ceff
Feed Name: Help Net Security
Threat Score
WordPress released security fixes addressing one critical SQL injection (CVE-2026-60137) and one high-severity REST API batch-route confusion that can lead to SQL injection and remote code execution (CVE-2026-63030). Affected releases include WordPress 6.9 (fixed in 6.9.5), 6.8 (first issue fixed in 6.8.6), and the 7.1 beta (fixed in beta2); temporary mitigations such as blocking anonymous access to the batch API or WAF rules are provided until updates are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
