CVE-2026-63030 CRITICAL

CVE-2026-63030: WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

Vendor Wordpress
Product WordPress
KEV Status Known Exploited
Published July 17, 2026
Last update July 21, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Explanation of Vulnerability in Simple Terms

02Summary

WordPress versions 6.9.0 through 6.9.4 contain a critical vulnerability that allows unauthenticated attackers to read sensitive data, modify site content, and disrupt service without any user interaction. The flaw requires only network access and affects all installations running the affected versions. Update to WordPress 6.9.5 or later immediately.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, and disrupt the site without authentication or user interaction.

Potential impact on your site

04Site Impact

Any WordPress site running 6.9.0–6.9.4 is at immediate risk of data theft, defacement, and downtime.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

CISA mandated remediation

06CISA Required Action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Key dates

07Disclosure timeline

July 17, 2026 CVE published
July 21, 2026 Record updated