Jump to the main content block

【Vulnerability Alert】WordPress Contains Two High-Risk Security Vulnerabilities (CVE-2026-60137 and CVE-2026-63030). Please Confirm and Apply Patches as Soon as Possible

publish date : 2026-07-31 update date : 2026-07-31

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026072709073131 Publication Time 2026-07-27 09:15:31
Incident Type ANA-Vulnerability Alert Discovery Time 2026-07-27 09:15:31
Impact Level Middle  
[Subject]
【Vulnerability Alert】WordPress Contains Two High-Risk Security Vulnerabilities (CVE-2026-60137 and CVE-2026-63030). Please Confirm and Apply Patches as Soon as Possible
[Content]

Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202607-00000006

Researchers discovered that WordPress contains two high-risk security vulnerabilities (CVE-2026-60137 and CVE-2026-63030), which are classified as an SQL Injection vulnerability and a REST API batch endpoint routing determination error, respectively. CVE-2026-60137 has been exploited by hackers. Please confirm and apply patches as soon as possible.

CVE-2026-60137: When a plugin or theme passes untrusted input to the affected function, it may result in SQL Injection.

CVE-2026-63030: An unauthenticated remote attacker may exploit the REST API batch endpoint routing determination error and combine it with CVE-2026-60137 to perform SQL Injection, thereby executing arbitrary code on the affected system.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

WordPress versions 6.8.0 to 6.8.5

WordPress versions 6.9.0 to 6.9.4

WordPress versions 7.0.0 to 7.0.1

[Recommended Actions]

The official vendor has released remediation updates for the vulnerabilities. Please upgrade to the following versions and refer to the official instructions for updating: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/

[Reference]

1.https://nvd.nist.gov/vuln/detail/CVE-2026-60137
2.https://nvd.nist.gov/vuln/detail/CVE-2026-63030
3.https://wordpress.org/news/2026/07/wordpress-7-0-2-release/

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: