CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Two new high severity WordPress vulnerabilities, patch immediately!

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2796

As cited

Copy frozen at (site build).

vulnerabilities

Two new high severity WordPress vulnerabilities, patch immediately!

WordPress released version 7.0.2 to address one critical and one high severity vulnerability. The issues include CVE-2026-60137, a facilitated SQL injection flaw, and a separate REST API batch-route confusion vulnerability leading to remote code execution. Both require immediate patching across affected WordPress 6.9 installations.

Why it matters: All WordPress site operators must apply version 7.0.2 immediately, as these vulnerabilities expose installations to SQL injection and remote code execution attacks that could compromise website integrity and user data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Two new high severity WordPress vulnerabilities, patch immediately!

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Two new high severity WordPress vulnerabilities, patch immediately!

WordPress 7.0.2 patches one critical and one high severity vulnerability affecting WordPress 6.9. CVE-2026-60137 involves a facilitated SQL injection issue, while a separate REST application programming interface (API) batch-route confusion flaw can lead to remote code execution (RCE). Both require immediate patching.

Why it matters: WordPress site administrators running version 6.9 must update immediately to close SQL injection and RCE vectors that attackers can exploit remotely without authentication.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Two new high severity WordPress vulnerabilities, patch immediately!

WordPress 7.0.2 patches one critical and one high severity vulnerability affecting WordPress 6.9. CVE-2026-60137 involves a facilitated SQL injection issue, while a separate REST application programming interface (API) batch-route confusion flaw can lead to remote code execution (RCE). Both require immediate patching.

Why it matters: WordPress site administrators running version 6.9 must update immediately to close SQL injection and RCE vectors that attackers can exploit remotely without authentication.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary