CVE Tools

Two new high severity WordPress vulnerabilities, patch immediately!

Help Net SecurityBy Sinisa Markovic

PatchWordPress

Our summary

WordPress has issued a security update in version 7.0.2 to resolve two significant vulnerabilities, including one critical flaw. The issues—CVE-2026-60137 (SQL injection) and another related to REST API batch-route confusion leading to potential remote code execution—were reported by multiple researchers. Sites running WordPress 6.9 or 6.8 are impacted, with updated versions 6.9.5 and 6.8.6 available. As a temporary workaround, administrators can restrict access to the batch API via plugins or WAF rules, though full protection requires applying the latest updates.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store