Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Help Net Security

Two new high severity WordPress vulnerabilities, patch immediately!

WordPress 7.0.2 patches two vulnerabilities: a facilitated SQL injection (CVE-2026-60137, CVSS 5.9) and a REST API batch-route confusion flaw leading to SQL injection and Remote Code Execution. The NVD lists CVE-2026-60137 with a CVSS 3.1 score of 5.9 (MEDIUM). The article states WordPress 6.9 is affected but does not provide a complete version range; administrators should upgrade to WordPress 7.0.2 immediately.
Read Full Article →

The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137 – A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber Which versions of WordPress are vulnerable? WordPress 6.9 is affected by … More → The post Two new high severity WordPress vulnerabilities, patch immediately! appeared first on Help Net Security .

Share this article