What the vulnerability does
01Description
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Explanation of Vulnerability in Simple Terms
02Summary
WordPress versions 6.9.0 through 6.9.4 contain a critical vulnerability that allows unauthenticated attackers to read sensitive data, modify site content, and disrupt service without any user interaction. The flaw requires only network access and affects all installations running the affected versions. Update to WordPress 6.9.5 or later immediately.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify content, and disrupt the site without authentication or user interaction.
Potential impact on your site
04Site Impact
Any WordPress site running 6.9.0–6.9.4 is at immediate risk of data theft, defacement, and downtime.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
CISA mandated remediation
06CISA Required Action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Key dates
07Disclosure timeline
July 17, 2026
CVE published
July 21, 2026
Record updated