Urgent Security Update Required for WordPress Users

Cybersecurity researchers have issued a stern warning regarding millions of WordPress-powered websites currently exposed to significant risks. This alert follows the discovery of two specific vulnerabilities that, when combined, provide attackers with a pathway to gain complete control over a website.


The Nature of the Security Flaws

The vulnerabilities, recently patched by the WordPress development team, include:

  • CVE-2026-60137: A medium-severity SQL injection flaw.
  • CVE-2026-63030: A critical-severity REST API batch-route confusion bug.

While these vulnerabilities may appear manageable in isolation, their combined impact is severe. According to reports, attackers have discovered how to chain these flaws together to achieve unauthenticated remote code execution, effectively granting them full administrative access to compromised sites.


Rapid Exploitation Observed

Security analysts at Knott have observed that threat actors began leveraging these flaws almost immediately after the patch was released. Within hours of the fix becoming available, instances of successful exploitation were already being recorded.


«By the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,» notes the team at Knott.

The researchers further emphasize that they are observing a widespread impact across a diverse global client base, affecting organizations of varying sizes and across multiple industries.


Protecting Your Infrastructure

These vulnerabilities are intrinsic to the WordPress core software, rather than being limited to specific third-party themes or plugins. Given that WordPress powers more than 50% of all websites globally, the scale of the potential threat is immense.

To mitigate the risk and secure your web assets, it is critical that administrators upgrade their installations to WordPress version 6.9.5 or newer immediately, as this update contains the necessary fixes to neutralize both security flaws.