CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Ninety minutes: watching attackers weaponize the WordPress core RCE

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6278

As cited

Copy frozen at (site build).

vulnerabilities

Ninety minutes: watching attackers weaponize the WordPress core RCE

WordPress released patches for two chained vulnerabilities (CVE-2026-60137 and CVE-2026-63030) affecting versions 6.8 through 7.0.1 that combine a SQL injection with REST application programming interface (API) route confusion to enable unauthenticated remote code execution. Within 90 minutes of patch release on July 17, attackers deployed exploitation attempts at scale, with Patchstack blocking over 65,000 attacks from 1,500+ IP addresses targeting unpatched installations. Analysis of the campaign revealed that most traffic was early-stage probing, but a small cluster of requests carried complete privilege-escalation chains to create administrator accounts, and subsequently attackers adapted their delivery methods to bypass URL-based security rules by moving the batch endpoint reference into POST body parameters.

Why it matters: WordPress site operators running 6.8 to 7.0.1 face immediate compromise risk requiring urgent patching to versions 7.0.2, 6.9.5, or 6.8.6; defenders need to update mitigation rules to inspect both URL and POST body parameters, as initial WAF rules were bypassable through alternative request shapes that began appearing in live attacks on July 21.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Ninety minutes: watching attackers weaponize the WordPress core RCE

WordPress released patches for two chained vulnerabilities (CVE-2026-60137 and CVE-2026-63030) affecting versions 6.8 through 7.0.1 that combine a SQL injection with REST application programming interface (API) route confusion to enable unauthenticated remote code execution. Within 90 minutes of patch release on July 17, attackers deployed exploitation attempts at scale, with Patchstack blocking over 65,000 attacks from 1,500+ IP addresses targeting unpatched installations. Analysis of the campaign revealed that most traffic was early-stage probing, but a small cluster of requests carried complete privilege-escalation chains to create administrator accounts, and subsequently attackers adapted their delivery methods to bypass URL-based security rules by moving the batch endpoint reference into POST body parameters.

Why it matters: WordPress site operators running 6.8 to 7.0.1 face immediate compromise risk requiring urgent patching to versions 7.0.2, 6.9.5, or 6.8.6; defenders need to update mitigation rules to inspect both URL and POST body parameters, as initial WAF rules were bypassable through alternative request shapes that began appearing in live attacks on July 21.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary