Skip to content
The Nexus
SECURITYJul 20 · 21:57 UTCTHE REGISTER

Attackers pummel critical WordPress vuln to create all sorts of mischief

Attackers are exploiting two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to enable pre-authentication remote code execution. The flaws, patched in WordPress versions 6.9.5 and 7.1 Beta 2, allow unauthenticated users to execute arbitrary code by chaining an SQL injection issue with a REST API route confusion bug. Security researchers observed widespread exploitation within hours of the patches being released.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting