CVE-2026-63030
🟠 Łataj w tym tygodniu
Błąd w WordPress umożliwia SQL Injection i zdalne wykonanie kodu.
CVSS
9.8
EPSS
8.9%
Exploit
none
Vendor
Opis źródłowy (NVD)
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
rce sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 8.9% |
| Opublikowano (NVD) | 2026-07-17 20:17:28 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-18 05:16:56 UTC |
Referencje
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q (contact@wpscan.com)
- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ (contact@wpscan.com)