WordPress Product Security Update Advisory
Overview
A security update has been released to address vulnerabilities in WordPress. Users of this product should update to the latest version.
Affected Versions
- WordPress versions: 6.8.0 Through 6.8.5.
- WordPress versions: 6.9.0 Through 6.9.4.
- WordPress versions: 7.0.0 Through 7.0.1.
Resolved Vulnerabilities
- CVE-2026-60137: SQL injection vulnerability in WordPress (a vulnerability where database queries are manipulated by exploiting input values).
- CVE-2026-63030: Batch-route confusion vulnerability in the WordPress REST API (an issue where request processing paths are confused).
Patch Versions
- CVE-2026-60137: WordPress 6.8.6, 6.9.5, 7.0.2.
- CVE-2026-63030: WordPress 6.9.5, 7.0.2.
Note
Follow the instructions on the reference site to update to the latest version that includes the Vulnerability Patch for these vulnerabilities.