As cited
Copy frozen at (site build).
vulnerabilities
Two new high severity WordPress vulnerabilities, patch immediately!
WordPress released version 7.0.2 to address one critical and one high severity vulnerability. The issues include CVE-2026-60137, a facilitated SQL injection flaw, and a separate REST API batch-route confusion vulnerability leading to remote code execution. Both require immediate patching across affected WordPress 6.9 installations.
Why it matters: All WordPress site operators must apply version 7.0.2 immediately, as these vulnerabilities expose installations to SQL injection and remote code execution attacks that could compromise website integrity and user data.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Two new high severity WordPress vulnerabilities, patch immediately!
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Two new high severity WordPress vulnerabilities, patch immediately!
WordPress 7.0.2 patches one critical and one high severity vulnerability affecting WordPress 6.9. CVE-2026-60137 involves a facilitated SQL injection issue, while a separate REST application programming interface (API) batch-route confusion flaw can lead to remote code execution (RCE). Both require immediate patching.
Why it matters: WordPress site administrators running version 6.9 must update immediately to close SQL injection and RCE vectors that attackers can exploit remotely without authentication.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Two new high severity WordPress vulnerabilities, patch immediately!
WordPress 7.0.2 patches one critical and one high severity vulnerability affecting WordPress 6.9. CVE-2026-60137 involves a facilitated SQL injection issue, while a separate REST application programming interface (API) batch-route confusion flaw can lead to remote code execution (RCE). Both require immediate patching.
Why it matters: WordPress site administrators running version 6.9 must update immediately to close SQL injection and RCE vectors that attackers can exploit remotely without authentication.
- Source published
- First seen by Cybersecurity Tracker