Sploitus Critical SQL Injection Vulnerability in WordPress Exploited in the Wild
Article Content
- •CVE-2026-63030 and CVE-2026-60137 allow remote code execution in WordPress.
- •Over 62,802 unique IPs have been observed exploiting these vulnerabilities.
- •Immediate patching is critical as many installations remain exposed.
A significant security flaw in WordPress, involving CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to execute remote code. This vulnerability affects WordPress versions 6.9.0 to 6.9.4 and has been actively exploited, with over 62,802 unique attacking IPs reported. The attack vector exploits a REST API batch-route confusion flaw that leads to SQL injection, enabling full site compromise. Public proof-of-concept (PoC) exploits are circulating, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026. Users are urged to update to patched versions immediately to mitigate risks. Temporary workarounds include blocking specific API endpoints and restricting anonymous access. The situation remains urgent as many sites may still be vulnerable due to delayed updates.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-60137 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Chinese Hackers Exploit Zyxel Switch Vulnerability CVE-2026-7273 A Chinese-speaking threat actor has exploited a stack-based buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 switches, compromising 996 devices across 48 countries since August 17, 2026. The vulnerability allows unauthenticated attackers to execute OS commands via crafted HTTP requests. Zyxel released…
Critical Unauthenticated Path Traversal Vulnerability in WordPress On September 22, 2026, WordPress released version 7.1.2 to address a critical unauthenticated path traversal vulnerability tracked as CVE-2026-87902. This flaw allows unauthenticated attackers to include local PHP files from outside the active theme directories, potentially leading to remote code execution under…