A critical unauthenticated remote code execution vulnerability, identified as CVE-2026-63030, has been discovered in WordPress Core, affecting millions of websites globally. The vulnerability allows an attacker to execute arbitrary code without authentication through the WordPress REST API batch endpoint, potentially leading to a complete compromise of the affected website and its data.
The issue impacts WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The WordPress project has released fixes in versions 6.9.5 and 7.0.2. A fix is also included in WordPress 7.1 Beta 2. Websites running versions earlier than 6.9 are not affected by this specific vulnerability.
The vulnerability was identified by researchers at Searchlight Cyber, who confirmed that it can be exploited remotely against a default WordPress installation without requiring any additional plugins. Cloudflare noted that the vulnerable code path is accessible when a persistent object cache is not in use.
Despite the GitHub Security Advisory classifying the severity as critical, the vulnerability has been assigned a CVSS score of 7.5. As of July 17, technical exploit details have not been publicly released by Searchlight Cyber, and there are no confirmed reports of in-the-wild exploitation. However, given the unauthenticated attack path and the widespread use of WordPress, security experts emphasize that the absence of public exploitation should not be interpreted as low risk.
WordPress maintainers have stated they are pushing forced updates for affected installations with automatic updates enabled. Site administrators are strongly advised to verify that all internet-facing WordPress websites have successfully updated to WordPress 6.9.5, 7.0.2, or another appropriate fixed release for their branch.
Due to the open-source nature of WordPress Core and the capabilities of current AI models to analyze code, it is considered highly probable that a public proof-of-concept exploit will become available in the near future. Organizations operating affected WordPress installations are urged to prioritize immediate upgrades as the most effective remediation. Workarounds are not currently recommended.






