LIVE · cybersecurity feed
Live wire

sql injection

CVE-2026-60137high

Two High-Severity WordPress Vulnerabilities Require Immediate Patching

WordPress version 6.9 has been impacted by two significant security flaws. One vulnerability allows for SQL injection, while the other, a REST API issue, could lead to remote code execution. Both have been addressed in the latest security release, version 7.0.2.

CVE-2026-60137critical

Cloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws

Cloudflare has released new Web Application Firewall (WAF) rules to protect WordPress sites from two severe vulnerabilities. These flaws include an unauthenticated remote code execution (RCE) bug in the REST API and a related SQL injection vulnerability, affecting specific versions of WordPress. While Cloudflare's WAF provides immediate protection, users are strongly advised to update their WordPress installations to the patched versions released by the WordPress security team.