Ninety minutes: watching attackers weaponize the WordPress core RCE
PoC publicWordPress CoreOur summary
A critical unauthenticated chain in WordPress Core led to rapid exploitation within 90 minutes of the patch being released. Attackers used CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API route confusion) to create admin accounts and achieve remote code execution. Over 65,000 attempts were blocked by Patchstack from more than 1,500 unique IPs. The vulnerabilities affect versions 6.8 through 7.0.1 and are now fixed in 7.0.2, 6.9.5, and 6.8.6. Sites that remain unpatched should monitor for suspicious admin accounts, unknown plugins, or unexpected PHP files.
Patchstack publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.