WordPress Product Security Update Advisory

WordPress Product Security Update Advisory

Overview

A security update has been released to address vulnerabilities in WordPress. Users of this product should update to the latest version.

Affected Versions

  • WordPress versions: 6.8.0 Through 6.8.5.
  • WordPress versions: 6.9.0 Through 6.9.4.
  • WordPress versions: 7.0.0 Through 7.0.1.

Resolved Vulnerabilities

  • CVE-2026-60137: SQL injection vulnerability in WordPress (a vulnerability where database queries are manipulated by exploiting input values).
  • CVE-2026-63030: Batch-route confusion vulnerability in the WordPress REST API (an issue where request processing paths are confused).

Patch Versions

  • CVE-2026-60137: WordPress 6.8.6, 6.9.5, 7.0.2.
  • CVE-2026-63030: WordPress 6.9.5, 7.0.2.

Note

Follow the instructions on the reference site to update to the latest version that includes the Vulnerability Patch for these vulnerabilities.