CRITICAL
CVE-2026-63030
CVSS
9.8
KEV
Description
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Summary dbcve.org
WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 contain a REST API batch endpoint route confusion vulnerability that, when chained with the separate author__not_in WP_Query SQL injection (CVE-2026-60137), enables unauthenticated attackers to inject arbitrary SQL queries and achieve remote code execution.
Mitigation
Update WordPress to version 6.9.5 or 7.0.2 or later to patch both the REST API route confusion and SQL injection vulnerabilities.
Weakness (CWE)
CWE-436
EPSS Score
97.27%
Probability of exploitation in next 30 days
99.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.