(Image credit: Shutterstock/David MG) WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeoverAdmins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacksMillions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.WordPress developers released a patch for two vulnerabilities - an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.The former is a medium-severity, 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical-severity, 9.8/10 flaw affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 of the world’s most popular website builder.Exploitation underwayAccording to The Register, these bugs are not that dangerous when looked at separately, since they are rather difficult to exploit. However, when chained together, they allow unauthenticated threat actors to execute malicious code remotely, which means full website takeover.Security researchers at Knott say threat actors picked up on the scent rather quickly.The patch was released on Friday, but “by the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Knott said.“From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.”Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!It is worth mentioning that these vulnerabilities affect WordPress directly, instead of different plugins or themes. WordPress is by far the most popular website builder platform in the world, powering more than half of all websites in existence today.To protect your assets, make sure to upgrade WordPress to version 6.9.5, since it contains fixes for both flaws. Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs
Full Article
Original Source
Read the full article at Techradar →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.