• 2 min read
WordPress bugs trigger active attacks and full site takeovers
Two newly patched WordPress flaws can be chained for unauthenticated remote code execution. Admins should update to 6.9.5 or newer now.

Image: TechRadar
Millions of WordPress sites may be exposed after attackers began exploiting two newly patched vulnerabilities that, when combined, can lead to unauthenticated remote code execution and a full website takeover.
WordPress has patched CVE-2026-60137, an SQL injection flaw rated 5.9/10, and CVE-2026-63030, a REST API batch-route confusion bug rated 9.8/10. The first affects WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2. The second affects 6.9.x before 6.9.5 and 7.0.x before 7.0.2.
According to The Register, each bug is relatively difficult to exploit on its own. Chained together, though, they let attackers run malicious code remotely without authentication.

Recommended reading
Deepfake scams have cost $3.7B, led by social media
Researchers at Knott say exploitation started almost immediately after the patch shipped on Friday.
“By the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public.”
Knott added that it is seeing widespread impact across organizations of every size and every vertical.
The risk is especially serious because the flaws affect WordPress core, not a third-party plugin or theme. As TechRadar notes, WordPress is the world’s most widely used website builder, powering more than half of all websites in existence today.
Admins should update to WordPress 6.9.5 or newer as soon as possible to get fixes for both vulnerabilities.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


