Skip to content
Critical SQL Injection Vulnerability in WordPress Exploited in the Wild

Critical SQL Injection Vulnerability in WordPress Exploited in the Wild

First seen 26 Sep 2026, 20:54 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 20:23 UTC
  • •CVE-2026-63030 and CVE-2026-60137 allow remote code execution in WordPress.
  • •Over 62,802 unique IPs have been observed exploiting these vulnerabilities.
  • •Immediate patching is critical as many installations remain exposed.

A significant security flaw in WordPress, involving CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to execute remote code. This vulnerability affects WordPress versions 6.9.0 to 6.9.4 and has been actively exploited, with over 62,802 unique attacking IPs reported. The attack vector exploits a REST API batch-route confusion flaw that leads to SQL injection, enabling full site compromise. Public proof-of-concept (PoC) exploits are circulating, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026. Users are urged to update to patched versions immediately to mitigate risks. Temporary workarounds include blocking specific API endpoints and restricting anonymous access. The situation remains urgent as many sites may still be vulnerable due to delayed updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 22h ago How this analysis works

Timeline

2026-07-17
CVE-2026-60137 published
A SQL injection vulnerability in WordPress was disclosed, affecting versions 6.8.0 to 6.8.5.
Article 2
2026-07-17
CVE-2026-63030 published
A REST API batch-route confusion flaw was disclosed, affecting WordPress versions 6.9.0 to 6.9.4.
Article 2
2026-07-21
CVE-2026-60137 added to CISA KEV
CISA confirmed active exploitation of the SQL injection vulnerability in the wild.
Article 2
2026-07-21
CVE-2026-63030 added to CISA KEV
CISA confirmed active exploitation of the REST API flaw in the wild.
Article 2
2026-09-26
Public PoC exploits circulating
Proof-of-concept exploits for the vulnerabilities are now publicly available, increasing risk.
Article 2
2026-09-27
Urgent patching recommended
Security experts urge immediate updates to patched WordPress versions to mitigate risks.
Article 1

More articles in this cluster (3)

Following this threat?

Track CVE-2026-60137 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed