CVE-2026-63030critical
Critical RCE Vulnerability in WordPress Core Affects Millions of Sites
A critical unauthenticated remote code execution vulnerability has been discovered in WordPress Core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The flaw, identified by Searchlight Cyber, allows attackers to execute code via the REST API batch endpoint without needing any user interaction or valid account. While exploit details are not yet public, the widespread use of WordPress makes this a significant risk, and urgent patching is recommended.