Critical CVE-2026-63030, CVE-2026-60137 — Two WordPress core bugs fixed in 7.0.2 chain together into remote code execution through the REST API batch endpoint, and both are on CISA's exploited list. Affected versions 6.8-7.0.1 and how to check your site.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: A SQL injection in WordPress core's WP_Query (author__not_in) plus a route-confusion bug in the REST API batch endpoint chain together into remote code execution. Both were fixed in WordPress 7.0.2 / 6.9.5 / 6.8.6 in July and were exploited within days. If you also haven't installed 7.1.2 for the September bug, do both now; the latest release covers everything.
| CVE-2026-63030 | REST API batch-route confusion → reaches the SQL injection → RCE. CVSS 9.8 |
|---|---|
| CVE-2026-60137 | SQL injection via author__not_in in WP_Query. CVSS 5.9 on its own |
| Affected | 60137: 6.8.0–6.8.5, 6.9.0–6.9.4, 7.0.0–7.0.1 · 63030: 6.9.0–6.9.4, 7.0.0–7.0.1 |
| Fixed in | 7.0.2 · 6.9.5 · 6.8.6 (released July 2026) |
| Exploited? | Yes, both on CISA KEV 2026-07-21 |
| See also | CVE-2026-87902 (September, fixed in 7.1.2) |
CVE-2026-60137: WP_Query, the function behind nearly every list of posts in WordPress, didn’t properly sanitise the author__not_in parameter. On its own that’s only exploitable if a plugin or theme passes untrusted input into it, which is why it scores a modest 5.9.
CVE-2026-63030: the REST API’s batch endpoint (/wp-json/batch/v1) could be confused into routing a request somewhere it shouldn’t, which lets an attacker deliver that unsanitised parameter to WP_Query themselves, with no vulnerable plugin needed. SQL injection on a WordPress database lets an attacker create admin users or alter options, and from an admin account, running code is trivial.
wp core version
Or Dashboard → Updates. Vulnerable if you’re on 6.8.0–6.8.5, 6.9.0–6.9.4 or 7.0.0–7.0.1. Anything 7.1.x is not affected by these two. But only 7.1.2 or later also has the September fix.
wp core update
wp core version
Minor-release auto-updates are on by default and should have handled this. Check anyway: hosts and some security plugins disable them. If you must stay on an older branch, the minimum versions are 7.0.2, 6.9.5 and 6.8.6, but you’ll still need the CVE-2026-87902 backport for that branch (7.0.6, 6.9.9, 6.8.10).
/wp-json/batch/v1 at your web server or WAF. Most sites never use the batch endpoint.wp user list --role=administrator: any admins you don’t recognise?/wp-json/batch/v1 or ?rest_route=/batch/v1.wp core verify-checksums and wp plugin verify-checksums --all for modified files; look for new PHP files in wp-content/uploads/.wp option get siteurl / home and active plugins for anything injected.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.