1 article with this tag
A REST API batch-endpoint route-confusion flaw in WordPress core (CVE-2026-63030, CWE-436) chains with the WP_Query author__not_in SQL injection (CVE-2026-60137, CWE-89) to reach unauthenticated SQLi → RCE (CVSS 9.8, in CISA KEV). Both are fixed in the same release. The real fix is updating core to 6.8.6 / 6.9.5 / 7.0.2, plus a compromise check. WordPress is core software with an enormous install base, so updating is the top priority.