CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
CVSS Score
9.8
EPSS Score
8.9%
EPSS Percentile
95th
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
| Vendor | wordpress |
| Product | wordpress |
| Ecosystems | |
| Industries | WebMedia |
| Published | Jul 17, 2026 |
| Last Updated | Jul 22, 2026 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for wordpress wordpress
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-63030.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
WordPress / WordPress
6.9.0 < 6.9.5 7.0.0 < 7.0.2
References
Credits
Adam Kues, Assetnote / Searchlight Cyber WordPress Security Team