Posted Date: 2026/07/27

【Vulnerability Alert】Two High-Risk Security Vulnerabilities Exist in WordPress (CVE-2026-60137 and CVE-2026-63030), Please Confirm and Patch as Soon as Possible

  • Subject: 【Vulnerability Alert】Two High-Risk Security Vulnerabilities Exist in WordPress (CVE-2026-60137 and CVE-2026-63030), Please Confirm and Patch as Soon as Possible


  • Description:
    • Forwarded from National Information Security Analysis and Sharing Center Information Security Alert NISAC-200-202607-00000006
    • Researchers have discovered two high-risk security vulnerabilities in WordPress (CVE-2026-60137 and CVE-2026-63030), which are classified as SQL Injection and a REST API batch endpoint routing misinterpretation issue, respectively. Among them, CVE-2026-60137 has already been exploited by hackers. Please verify and patch as soon as possible.
    • CVE-2026-60137: When a plugin or theme passes untrusted input into affected functions, it may lead to SQL injection.
    • CVE-2026-63030: An unauthenticated remote attacker could exploit the REST API batch endpoint routing misinterpretation issue, combined with CVE-2026-60137, to execute SQL injection and subsequently execute arbitrary code on the affected system.
  • Affected Platforms:
    • WordPress versions 6.8.0 to 6.8.5
    • WordPress versions 6.9.0 to 6.9.4
    • WordPress versions 7.0.0 to 7.0.1
  • Recommendations:
  • References:

Computer and Communication Center
Network System Division