Cyber Resilience
← All news

Two new high severity WordPress vulnerabilities, patch immediately!

Our takeWordPress 7.0.2 patches CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API RCE) — both already under active exploitation per SecurityWeek and CCCS. If you run WordPress, update now; this is a huge share of lean-IT sites.
Sources (8)
What this means for you — Security leader:Patch WordPress core to 7.0.2 (or the 6.9.5/6.8.6 backports) across every managed site now; active exploitation is already reported, so treat this as emergency-change, not next patch cycle.
What this means for you — Lean IT orgs:If your website runs WordPress, update it to the latest version today — most hosts push this automatically, but confirm it happened since attacks are already underway.
What this means for you — MSP:Roll WordPress core updates (7.0.2/6.9.5/6.8.6) to all client sites this week and check web logs for exploitation attempts on CVE-2026-60137 and CVE-2026-63030, since exploitation started soon after disclosure.
What this means for you — Researcher:The REST API batch-route confusion chain (CVE-2026-63030) that escalates SQLi to RCE is worth digging into — SecurityWeek confirms in-the-wild exploitation, and the route-confusion pattern may recur in other plugin/core API interactions.