💻
Critical WordPress vulnerabilities leave millions of sites open to full takeover
💻 Technology

Critical WordPress vulnerabilities leave millions of sites open to full takeover

WordPress has patched two dangerous vulnerabilities: CVE-2026-60137, an SQL injection bug rated medium severity (5.9/10), and CVE-2026-63030, a critical REST API batch-route confusion flaw rated 9.8/10. When chained together, they allow unauthenticated remote code execution and full site takeover. Admins are urged to upgrade immediately to WordPress 6.9.5 or newer, as both flaws are being actively exploited in the wild.

Comments

No comments yet