Security0 views

WordPress Security Alert: Critical SQL Injection and API Vulnerabilities Under Active Exploit

WordPress has issued a critical security alert warning that hackers are actively exploiting two newly patched vulnerabilities affecting millions of sites worldwide.

The first vulnerability, CVE-2026-60137, is a SQL injection flaw that allows attackers to access sensitive data, including administrator password hashes. The second, CVE-2026-63030, enables attackers to manipulate the normal flow of API requests and perform actions that typically require elevated privileges.

Both vulnerabilities impact WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. If you're running any of these versions, updating immediately is essential to protect your site from active exploitation.