CRITICAL

CVE-2026-63030

Wordpress WordPress 2026-07-17 CVSS v3.1
CVSS
9.8
KEV

Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Summary dbcve.org

WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 contain a REST API batch endpoint route confusion vulnerability that, when chained with the separate author__not_in WP_Query SQL injection (CVE-2026-60137), enables unauthenticated attackers to inject arbitrary SQL queries and achieve remote code execution.

Mitigation

Update WordPress to version 6.9.5 or 7.0.2 or later to patch both the REST API route confusion and SQL injection vulnerabilities.

Weakness (CWE)

CWE-436

EPSS Score

97.27%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE