Unpatched Internet-facing WordPress Core sites are already in automated attack traffic, so this is no longer a theoretical takeover path. The useful warning is not the bug itself. It is that once a site was reachable during the window, patching alone may not remove the attacker state left behind.
FortiGuard says it blocked 4,649 exploitation attempts in the past 24 hours and saw 88,452 detections over seven days. The chain combines CVE-2026-63030, a REST API batch route confusion issue, with CVE-2026-60137, a WP_Query SQL injection, and the fixed versions are 6.8.6, 6.9.5, and 7.0.2 or later.
That scale points to automated scanning and likely persistent compromise on exposed sites, not a niche proof of concept. For operators of public WordPress estates, the real risk is attacker presence that survives the patch as web shells or unauthorized admin accounts.