Threat Advisory

WordPress Pre-auth RCE Lets Attackers Read Arbitrary Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-63030 (CVSS 9.8 — Critical): The vulnerability is a pre-auth RCE chain built on an SQL injection issue that can be exploited through the unauthenticated REST batch endpoint at, allowing attackers to inject rogue parameters into WP_Query and ultimately reach database admin password hashes.

CVE-2026-60137 (CVSS 5.9 — Medium): The vulnerability is a blind SQL injection reachable before authentication, which can be used to bypass method allow-lists and slip a rogue parameter into WP_Query. These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins. These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-63030 (CVSS 9.8 — Critical): The vulnerability is a pre-auth RCE chain built on an SQL injection issue that can be exploited through the unauthenticated REST batch endpoint at, allowing attackers to inject rogue parameters into WP_Query and ultimately reach database admin password hashes.

CVE-2026-60137 (CVSS 5.9 — Medium): The vulnerability is a blind SQL injection reachable before authentication, which can be used to bypass method allow-lists and slip a rogue parameter into WP_Query. These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins. These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins.[emaillocker id="1283"]

These vulnerabilities collectively present a significant risk to WordPress administrators, particularly those running stock installs without plugins.

RECOMMENDATION:

We recommend you to update WordPress to version 6.8.6.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu