WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
Description
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Affected Products
Vendor
Product
Versions
wordpress
wordpress
6.9.0, 7.0.0
Also Affects
Downstream vendors/products affected by this vulnerability
Added affected version 6.8.6 (previously missing) and supplemented tags with specific AI model details (GPT5.6 Sol Ultra), discoverer information (Searchlight Cyber), and confirmation of multi-stage exploit chain methodology used in WP2Shell
tags
via Infosecurity Magazine
v11Tier D66d ago
Added significant technical details about the exploit chain mechanics including cache poisoning, customize changeset manipulation, and authentication bypass techniques, plus new tags related to AI-assisted exploit development and multi-stage exploitation.
tags
via Infosecurity Magazine
v10Tier B66d ago
Added WordPress 7.1.0-beta2 as affected version and added CERT-FR confirmation tag
affectedVersionstags
via CERT-FR
v9Tier B66d ago
Added newly affected versions 6.8.6 and 7.1.0 (7.1 beta2) to the affected versions list based on CERT-FR advisory.
affectedVersions
via CERT-FR
v8Tier D66d ago
Clarified affected versions to exclude 6.8.x series (not mentioned in article), added CVE-2026-63030 identifier, and added tags documenting confirmed in-the-wild exploitation by multiple security firms and availability of Cloudflare mitigation rules.
tags
via SecurityWeek
v7Tier D67d ago
Added CWE-942 (route confusion), MITRE ATT&CK techniques T1190 and T1059.001, and new tags reflecting public exploit release and forced auto-update status.
cweIdsmitreAttacktags
via BleepingComputer
v6Tier D67d ago
Updated affected versions list to be more precise (6.9.0-6.9.4 and 7.0.0-7.0.1), added MITRE ATT&CK technique T1190, and added 'pre-authentication' and 'public-exploit' tags reflecting public PoC release.
affectedVersionstags
via BleepingComputer
v5Tier E68d ago
Article identifies CVE-2026-63030 as the primary batch endpoint vulnerability (distinct from CVE-2026-60137 SQL injection), and indicates CWE-78 (OS Command Injection) is relevant to the RCE chain mechanism.
cweIds
via Reddit r/cybersecurity
v4Tier D68d ago
Added affected versions 6.8.x, identified CWE-89 (SQL Injection), and added wp2shell tag and batch-endpoint context. Article clarifies that versions before 6.8 are unaffected, implying 6.8.0-6.8.5 are vulnerable.
affectedVersionscweIdstags
via Heise Security
v3Tier C68d ago
Updated severity from HIGH to CRITICAL per GitHub Security Advisory; expanded affected versions to include 6.9.1-6.9.4 and 7.0.1; added tags indicating unauthenticated attack path and object cache bypass requirement.
severityaffectedVersionstags
via Rapid7 Blog
v2Tier C68d ago
Updated severity to CRITICAL, added CVSS estimate of 9.0, and expanded affected versions to include 6.9.4 and 7.0.1.