Vulnerabilities · 42 days ago

WordPress Core Faces Automated Mass Exploitation

Unpatched Internet-facing WordPress Core sites are already in automated attack traffic, so this is no longer a theoretical takeover path. The useful warning is not the bug itself. It is that once a site was reachable during the window, patching alone may not remove the attacker state left behind.

FortiGuard says it blocked 4,649 exploitation attempts in the past 24 hours and saw 88,452 detections over seven days. The chain combines CVE-2026-63030, a REST API batch route confusion issue, with CVE-2026-60137, a WP_Query SQL injection, and the fixed versions are 6.8.6, 6.9.5, and 7.0.2 or later.

That scale points to automated scanning and likely persistent compromise on exposed sites, not a niche proof of concept. For operators of public WordPress estates, the real risk is attacker presence that survives the patch as web shells or unauthorized admin accounts.

CVE-2026-60137

NVD KEV

Known exploited · CISA KEV

CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 78% (100th percentile).

CISA federal remediation date Aug 4

CVE-2026-63030

NVD KEV

Known exploited · CISA KEV

CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…

CISA federal remediation date Jul 24 · date passed

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-08-09

Editions

Related stories