CVE-2026-63030 (CVSS 9.8 — Critical): The vulnerability is a pre-auth RCE chain built on an SQL injection issue that can be exploited through the unauthenticated REST batch endpoint at, allowing attackers to inject rogue parameters into WP_Query and ultimately reach database admin password hashes.
CVE-2026-60137 (CVSS 5.9 — Medium): The vulnerability is a blind SQL injection reachable before authentication, which can be used to bypass method allow-lists and slip a rogue parameter into WP_Query. These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins. These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins.[/subscribe_to_unlock_form]
CVE-2026-63030 (CVSS 9.8 — Critical): The vulnerability is a pre-auth RCE chain built on an SQL injection issue that can be exploited through the unauthenticated REST batch endpoint at, allowing attackers to inject rogue parameters into WP_Query and ultimately reach database admin password hashes.
CVE-2026-60137 (CVSS 5.9 — Medium): The vulnerability is a blind SQL injection reachable before authentication, which can be used to bypass method allow-lists and slip a rogue parameter into WP_Query. These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins. These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins.[emaillocker id="1283"]
These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins.
We recommend you to update WordPress to version 6.8.6.
The following reports contain further technical details:
[/emaillocker]