
[CIVN-2026-0373] Multiple Vulnerabilities in WordPress
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in WordPress
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
WordPress versions prior to 7.0.2
Overview
Multiple vulnerabilities have been reported in WordPress, which could allow an attacker to perform SQL injection attack, or execute arbitrary code on the targeted system.
Target Audience:
Users of affected WordPress versions.
Risk Assessment:
Risk of SQL injection attacks and remote code execution (RCE).
Impact Assessment:
Potential for unauthorized access, execution of arbitrary code, privilege escalation, and full compromise.
Description
WordPress is an open-source content management system (CMS) used to build websites and blogs.
Multiple vulnerabilities exist in WordPress due to a REST API batch endpoint route interpretation conflict (route confusion) and improper sanitization of the author__not_in parameter in WP_Query.
Successful exploitation of these vulnerabilities could allow an attacker to perform SQL injection attack, or execute arbitrary code on the targeted system.
Solution
Apply the necessary patches and updates as provided by vendor:
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
Vendor Information
WordPress
https://wordpress.org/
References
WordPress
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
CVE Name
CVE-2026-60137
CVE-2026-63030
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpfipMACgkQ3jCgcSdc
ys9ORBAAiHPO+iwUYutbCfY33UTpIlKxVu/MBlN57VUB3RpVU8G//5pQpFWSjW9Q
yKhx4yHISywGzx8W8xEFvF/Nf1IARP18/BvYCkTZMPaZTNCiOMmXDUzIRfxTLJsD
taJo4FjmvFEGVLynJ8spRIuoFHhOiGJEtJLskbeROo7ujWA3TcbEplPN4LOCuCOs
F7QDdmhUPkgAEXQYpesJRPeuqjUxTac0hC91nlVSvP5x0JFVG7OvqwYviwCIXjSv
GF3dC91yI30t0zWbdOFHmFMQBrDmCv3+vBs9syC7e3G897cTGsrG16GmpgLR4PNT
OfZn+5hDasO6yrgRKz6v8Zc8iLwpja5WNsQu8Y+9bH4Y7vOjKpSwg3F4ECchkSNT
aShtLzw4Rg3Ue6kvD4Bib1UY8sI2P0wYtPJw1UoSiH2ieJACp+y2Xg5kbJT6Mj5v
NA1wYqlLwGwpwzW7vOwTkhz1cufrbMiA7wWsoqr1IfSxHyFQArHrj9Le+m0mz6S0
JPfHaJRI4ccTCojEUpAxLImjtcgnu1QEaJlMAaa30jbrt9wQ1lvKJaev4WVzGciv
l4IjqbSfgXZedpxajgZ08503CMurE/g2RHzIRVhgPSWVQfp/EiAjvQQ+oIfYCzWN
40QHls2hRy7ySY4OiELNBSpnqC14w55bUnSeur0eQSe84Lfm+SA=
=84tY
—–END PGP SIGNATURE—–


