Breaking
NVIDIA Nemotron 3.5 Lightning Turns a Sparse Agent Model into a SageMaker JumpStart Catalog Item What Is AI Agent Security? How Autonomous AI Changes the Attack Surface AI Agent for Cyber Security: What It Does, Where It Fails, and How to Deploy One Safely The Open-Weight LLM Power Map: Who Builds, Funds and Controls the Leading Models Open Source LLM or Just Open Weights? Check the License Before You Deploy Best Open Source LLM by Task: The Test Protocol for Coding, Research, Writing, and Reasoning NVIDIA Nemotron 3.5 Lightning Turns a Sparse Agent Model into a SageMaker JumpStart Catalog Item What Is AI Agent Security? How Autonomous AI Changes the Attack Surface AI Agent for Cyber Security: What It Does, Where It Fails, and How to Deploy One Safely The Open-Weight LLM Power Map: Who Builds, Funds and Controls the Leading Models Open Source LLM or Just Open Weights? Check the License Before You Deploy Best Open Source LLM by Task: The Test Protocol for Coding, Research, Writing, and Reasoning
Security

Urgent WordPress Security Advisory: Critical RCE Chain Exploited In The Wild (CVE-2026-63030 & CVE-2026-60137)

Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, combine to allow unauthenticated attackers Remote Code Execution. Patch immediately as PoC exploits are public and in-the-wild attacks have begun.

By Staff Writer

Urgent WordPress Security Advisory: Critical RCE Chain Exploited In The Wild (CVE-2026-63030 & CVE-2026-60137)

A pair of severe vulnerabilities within WordPress, designated CVE-2026-63030 and CVE-2026-60137, demand immediate attention from all administrators. Combined, these flaws permit unauthenticated attackers to execute arbitrary code on affected sites, essentially granting them full control. Proof-of-Concept (PoC) exploit code is publicly available, and reports indicate active exploitation in the wild, underscoring the urgency for patching.

Unpacking the Vulnerabilities: Batch-Route Confusion and SQL Injection

Understanding the mechanism of these vulnerabilities is crucial for grasping their destructive potential. This isn’t just about a single flaw; it’s a chain reaction.

CVE-2026-63030: The Unauthenticated Gateway

Discovered by Adam Kues at Assetnote and Searchlight Cyber, CVE-2026-63030 is an unauthenticated batch-route confusion vulnerability. Simply put, this flaw allows attackers to bypass authentication checks that would normally protect certain API endpoints. The WordPress REST API includes a “batch” endpoint designed to handle multiple API requests efficiently. This vulnerability confuses the system regarding the authentication status of requests routed through this batch handler, thereby enabling unauthorized access to actions typically reserved for authenticated users. Cloudflare’s advisory specifically notes that this can lead to pre-authentication RCE when a persistent object cache is not in use, a common configuration for many WordPress installations.

CVE-2026-60137: The SQL Injection Lever

Independently identified by the TF1T, dtro, and haongo team, CVE-2026-60137 is an authenticated SQL injection vulnerability. On its own, this flaw requires an attacker to already possess valid user credentials to exploit. SQL injection permits an attacker to insert malicious SQL code into input fields, manipulating the database queries. This can lead to unauthorized data retrieval, modification, or even deletion, including sensitive information like user credentials.

The Dangerous Exploit Chain: From Bypass to Total Control

Here’s the thing: while CVE-2026-60137 is an authenticated vulnerability, CVE-2026-63030 changes everything. The batch-route confusion acts as an authentication bypass. This means an unauthenticated attacker can leverage CVE-2026-63030 to effectively “authenticate” to the system, thereby unlocking the SQL injection vulnerability, CVE-2026-60137, which would otherwise be inaccessible. Once the SQL injection is exploitable, attackers can:

  • Dump the entire WordPress database, including password hashes for all users.
  • Crack these password hashes to obtain plaintext administrative credentials.
  • Log in as an administrator.
  • Utilize the theme and plugin editor functionalities, which are available to administrators, to upload and execute arbitrary PHP code. This culminates in a full Remote Code Execution (RCE) on the server.

This entire process, from initial unauthenticated access to full server compromise, has a low barrier to entry thanks to readily available PoC exploits on platforms like GitHub. Early exploitation attempts have already been observed, making swift action paramount.

Affected WordPress Versions and Essential Patches

The severity of this exploit chain necessitates immediate patching. Several WordPress versions are at risk:

  • WordPress 6.9: Vulnerable to both CVE-2026-63030 and CVE-2026-60137. Administrators must update to WordPress 6.9.5 immediately.
  • WordPress 6.8: Primarily affected by CVE-2026-60137. Update to WordPress 6.8.6 to apply the fix. While 6.8 is not directly vulnerable to the batch-route confusion, upgrading to the latest secure branch is always prudent.
  • WordPress 7.1 Beta: Both vulnerabilities affect early beta releases. WordPress 7.1 Beta 2 contains the necessary patches.

Notably, versions of WordPress prior to 6.8 are not susceptible to these specific issues. However, running older, unsupported WordPress versions is a significant security risk in itself and should be avoided.

Emergency Mitigation Strategies (Temporary)

If patching isn’t immediately feasible, temporary mitigation measures can reduce exposure, though they are not long-term solutions and may cause functional disruptions. Searchlight Cyber security researchers suggest:

  • WAF (Web Application Firewall) Rules: Block requests to /wp-json/batch/v1 and ?rest_route=/batch/v1 at the WAF level. This directly targets the batch-route confusion vector.
  • REST API Blocking Plugin: Install a WordPress plugin designed to block anonymous access to the REST API entirely. Be aware, this might break legitimate functionalities relying on the REST API.

These are strictly emergency steps. Prioritize a full update as soon as humanly possible.

Beyond the Patch: Proactive Security Measures

While patching these critical flaws is non-negotiable, it also serves as a stark reminder of the continuous need for robust cybersecurity hygiene. Consider these proactive steps to enhance your WordPress security service:

  • Regular Updates: Keep WordPress core, themes, and plugins updated. Many vulnerabilities stem from outdated software.
  • Security Audits: Periodically conduct or commission security audits of your WordPress installation and underlying server infrastructure.
  • Strong Access Controls: Implement strong, unique passwords for all users, especially administrators. Enforce two-factor authentication (2FA) for every login.
  • Least Privilege Principle: Grant users only the minimum necessary permissions to perform their tasks. Avoid giving editor or administrator roles to those who don’t absolutely need them.
  • Hardening WordPress: Implement additional security measures like disabling file editing from the dashboard, restricting file permissions, and using security plugins that offer extra layers of protection.
  • Reliable Backups: Maintain regular, off-site backups of your entire WordPress installation, including the database and files. Test restoration procedures periodically.
  • Incident Response Plan: Have a clear plan for what to do if your site is compromised. Knowing who to contact and what steps to take can minimize damage. Even experienced organizations, like the US cybersecurity agency CISA, had to build their incident playbook during an incident, illustrating how critical preparation is.
  • Logging and Monitoring: Implement comprehensive logging and monitor these logs for suspicious activities. Early detection can prevent full compromise.

Conclusion

The confluence of CVE-2026-63030 and CVE-2026-60137 presents an exceptionally dangerous threat to WordPress sites. The ability for an unauthenticated attacker to achieve Remote Code Execution is among the most severe outcomes in web security. Given the active exploitation and public availability of PoC code, deferring action is not an option. Patch your WordPress installations to the recommended versions immediately. Beyond this critical fix, recommit to a holistic and proactive approach to your website security. Your diligence now will prevent significant headaches and potential damage down the line.

More from the Forge

Editorial illustration for AI Agent for Cyber Security: What It Does, Where It Fails, and How to Deploy One Safely
AI

AI Agent for Cyber Security: What It Does, Where It Fails, and How to Deploy One Safely

An AI agent for cyber security is not a chatbot with a security skin. In the sense used across most current security tooling, it is a language model wired to tools, memory, and an orchestration loop that selects its own next step within limits a human sets. This explainer breaks the agent into its component layers, maps the defensive tasks it is being pointed at, examines how the same architecture serves attackers, details the new attack surface the agent itself creates, and closes with an…

Editorial illustration for What Is AI Agent Security? How Autonomous AI Changes the Attack Surface
AI

What Is AI Agent Security? How Autonomous AI Changes the Attack Surface

AI agent security is not chatbot safety. Once a language model gains tools, memory, credentials, and the authority to act, it becomes a non-human identity with real reach into your systems. This explainer defines the discipline, maps the threat classes, explains why conventional controls are necessary but not sufficient, and gives a practical control checklist covering identity, permissions, approval gates, isolation, validation, logging, and testing.

Human cybersecurity analyst and abstract AI system working in complementary roles across a modern operations environment
Security

Will Cybersecurity Be Replaced by AI? Risks, Defenses, and What Changes Next

"Will cybersecurity be replaced by AI" is a question about tasks, not about a profession disappearing. This analysis separates what AI might automate from what still needs accountable human review, examines defensive and adversarial uses, covers the risk classes AI systems add, and sets out what to watch next — while being explicit about which claims the supplied evidence supports and which sections still need primary sourcing before publication.