Patch released WordPress web-app rce
Two new high severity WordPress vulnerabilities, patch immediately!
CVE Tools coverage
WordPress has issued a security update in version 7.0.2 to resolve two significant vulnerabilities, including one critical flaw. The issues—CVE-2026-60137 (SQL injection) and another related to REST API batch-route confusion leading to potential remote code execution—were reported by multiple researchers. Sites running WordPress 6.9 or 6.8 are impacted, with updated versions 6.9.5 and 6.8.6 available. As a temporary workaround, administrators can restrict access to the batch API via plugins or WAF rules, though full protection requires applying the latest updates.