Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026072709073131 | Publication Time | 2026-07-27 09:15:31 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-07-27 09:15:31 |
| Impact Level | Middle | ||
| [Subject] 【Vulnerability Alert】WordPress Contains Two High-Risk Security Vulnerabilities (CVE-2026-60137 and CVE-2026-63030). Please Confirm and Apply Patches as Soon as Possible |
|||
| [Content]
Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202607-00000006 Researchers discovered that WordPress contains two high-risk security vulnerabilities (CVE-2026-60137 and CVE-2026-63030), which are classified as an SQL Injection vulnerability and a REST API batch endpoint routing determination error, respectively. CVE-2026-60137 has been exploited by hackers. Please confirm and apply patches as soon as possible. CVE-2026-60137: When a plugin or theme passes untrusted input to the affected function, it may result in SQL Injection. CVE-2026-63030: An unauthenticated remote attacker may exploit the REST API batch endpoint routing determination error and combine it with CVE-2026-60137 to perform SQL Injection, thereby executing arbitrary code on the affected system. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
WordPress versions 6.8.0 to 6.8.5 WordPress versions 6.9.0 to 6.9.4 WordPress versions 7.0.0 to 7.0.1 |
|||
|
[Recommended Actions] The official vendor has released remediation updates for the vulnerabilities. Please upgrade to the following versions and refer to the official instructions for updating: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ |
|||
|
[Reference] 1.https://nvd.nist.gov/vuln/detail/CVE-2026-60137 |
|||