
WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity) When chained, the bugs enabled unauthenticated remote code execution, allowing full site…
View original source — TechRadar ↗


