WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
| Vendor | Product | Versions |
|---|---|---|
| wordpress | wordpress | 6.9.0, 7.0.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | wordpress | cert_advisory | 90% |
Loading…
Added affected version 6.8.6 (previously missing) and supplemented tags with specific AI model details (GPT5.6 Sol Ultra), discoverer information (Searchlight Cyber), and confirmation of multi-stage exploit chain methodology used in WP2Shell
Added significant technical details about the exploit chain mechanics including cache poisoning, customize changeset manipulation, and authentication bypass techniques, plus new tags related to AI-assisted exploit development and multi-stage exploitation.
Added WordPress 7.1.0-beta2 as affected version and added CERT-FR confirmation tag
Added newly affected versions 6.8.6 and 7.1.0 (7.1 beta2) to the affected versions list based on CERT-FR advisory.
Clarified affected versions to exclude 6.8.x series (not mentioned in article), added CVE-2026-63030 identifier, and added tags documenting confirmed in-the-wild exploitation by multiple security firms and availability of Cloudflare mitigation rules.
Added CWE-942 (route confusion), MITRE ATT&CK techniques T1190 and T1059.001, and new tags reflecting public exploit release and forced auto-update status.
Updated affected versions list to be more precise (6.9.0-6.9.4 and 7.0.0-7.0.1), added MITRE ATT&CK technique T1190, and added 'pre-authentication' and 'public-exploit' tags reflecting public PoC release.
Article identifies CVE-2026-63030 as the primary batch endpoint vulnerability (distinct from CVE-2026-60137 SQL injection), and indicates CWE-78 (OS Command Injection) is relevant to the RCE chain mechanism.
Added affected versions 6.8.x, identified CWE-89 (SQL Injection), and added wp2shell tag and batch-endpoint context. Article clarifies that versions before 6.8 are unaffected, implying 6.8.0-6.8.5 are vulnerable.
Updated severity from HIGH to CRITICAL per GitHub Security Advisory; expanded affected versions to include 6.9.1-6.9.4 and 7.0.1; added tags indicating unauthenticated attack path and object cache bypass requirement.
Updated severity to CRITICAL, added CVSS estimate of 9.0, and expanded affected versions to include 6.9.4 and 7.0.1.
Initial creation