Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs
Date:
Tue, 21 Jul 2026 13:05:00 +0000
Description:
Hackers are chaining together two newly discovered flaws to achieve remote code execution.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter WordPress patches two flaws: CVE202660137 (SQL injection, medium severity) and CVE202663030 (REST API batchroute confusion, critical severity) When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.
WordPress developers released a patch for two vulnerabilities - an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030. The former is a medium-severity, 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical-severity, 9.8/10 flaw affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 of the worlds most popular website builder . Latest Videos From Watch full video here: Exploitation underway According to The Register , these bugs are not that dangerous when looked at separately, since they are rather difficult to exploit. However, when chained together, they allow unauthenticated threat actors to execute malicious code remotely, which means full website takeover.
Security researchers at Knott say threat actors picked up on the scent rather quickly. You may like Over a million WordPress sites hit in plugin flaw so patch now or face the consequences WordPress users beware experts claim
sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin Over 1 million WordPress sites at risk after popular plugins hacked
The patch was released on Friday, but by the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public, Knott said.
From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
It is worth mentioning that these vulnerabilities affect WordPress directly, instead of different plugins or themes. WordPress is by far the most popular website builder platform in the world, powering more than half of all
websites in existence today.
To protect your assets, make sure to upgrade WordPress to version 6.9.5,
since it contains fixes for both flaws. The best antivirus for all budgets
Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/experts-warn-millions-of-wordpress-webs ites-could-be-at-risk-following-reveal-of-worrying-bugs
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)