๐Ÿ” CVE Alert

CVE-2026-63030

CRITICAL 9.8 โš ๏ธ CISA KEV

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

CVSS Score
9.8
EPSS Score
8.9%
EPSS Percentile
95th

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Vendor wordpress
Product wordpress
Ecosystems
Industries
WebMedia
Published Jul 17, 2026
Last Updated Jul 22, 2026
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for wordpress wordpress

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-63030.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

WordPress / WordPress
6.9.0 < 6.9.5 7.0.0 < 7.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q wordpress.org: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030

Credits

Adam Kues, Assetnote / Searchlight Cyber WordPress Security Team