LIVE · cybersecurity feed
Live wire
CVE-2026-63030critical

Critical RCE Vulnerability in WordPress Core Affects Millions of Sites

A critical unauthenticated remote code execution vulnerability has been discovered in WordPress Core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The flaw, identified by Searchlight Cyber, allows attackers to execute code via the REST API batch endpoint without needing any user interaction or valid account. While exploit details are not yet public, the widespread use of WordPress makes this a significant risk, and urgent patching is recommended.

zeroday.news · 15d ago

A critical unauthenticated remote code execution vulnerability, identified as CVE-2026-63030, has been discovered in WordPress Core, affecting millions of websites globally. The vulnerability allows an attacker to execute arbitrary code without authentication through the WordPress REST API batch endpoint, potentially leading to a complete compromise of the affected website and its data.

The issue impacts WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The WordPress project has released fixes in versions 6.9.5 and 7.0.2. A fix is also included in WordPress 7.1 Beta 2. Websites running versions earlier than 6.9 are not affected by this specific vulnerability.

The vulnerability was identified by researchers at Searchlight Cyber, who confirmed that it can be exploited remotely against a default WordPress installation without requiring any additional plugins. Cloudflare noted that the vulnerable code path is accessible when a persistent object cache is not in use.

Despite the GitHub Security Advisory classifying the severity as critical, the vulnerability has been assigned a CVSS score of 7.5. As of July 17, technical exploit details have not been publicly released by Searchlight Cyber, and there are no confirmed reports of in-the-wild exploitation. However, given the unauthenticated attack path and the widespread use of WordPress, security experts emphasize that the absence of public exploitation should not be interpreted as low risk.

WordPress maintainers have stated they are pushing forced updates for affected installations with automatic updates enabled. Site administrators are strongly advised to verify that all internet-facing WordPress websites have successfully updated to WordPress 6.9.5, 7.0.2, or another appropriate fixed release for their branch.

Due to the open-source nature of WordPress Core and the capabilities of current AI models to analyze code, it is considered highly probable that a public proof-of-concept exploit will become available in the near future. Organizations operating affected WordPress installations are urged to prioritize immediate upgrades as the most effective remediation. Workarounds are not currently recommended.

wordpressrcevulnerabilityrest apipatching
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]