Researchers have discovered two high-risk security vulnerabilities in WordPress (CVE-2026-60137 and CVE-2026-63030), which are classified as SQL Injection and a REST
API batch endpoint routing misinterpretation issue, respectively. Among them, CVE-2026-60137 has already been exploited by hackers. Please verify and patch as soon as possible.