Critical WordPress Security Patches Released – Update Now

On July 17, 2026, the WordPress Security Team announced critical updates to address two vulnerabilities: CVE-2026-60137 (unauthenticated SQL injection) and CVE-2026-63030 (unauthenticated remote code execution). These vulnerabilities pose serious risks, allowing unauthorized users to execute code on your server.

Key Takeaways

  • WordPress core updates released on July 17, 2026, fix critical vulnerabilities.
  • Ensure your site is updated to versions 6.8.6, 6.9.5, or 7.0.2 immediately.
  • Automatic updates are in place, but verify your site’s status to avoid risks.

Description of Vulnerabilities

CVE-2026-60137 allows attackers to exploit SQL injection through the ‘author__not_in’ parameter, potentially exposing sensitive data. CVE-2026-63030 can be chained with the first vulnerability, enabling remote code execution via the REST API. Both vulnerabilities affect WordPress versions 6.8.X, 6.9.X, and 7.0.X.

Recommended Actions

WordPress has initiated automatic updates for sites running vulnerable versions. However, it is crucial for site owners to manually verify that their installations have been updated to one of the patched versions: 6.8.6, 6.9.5, or 7.0.2. Failing to do so could leave your site exposed to significant security risks.

Summary

These updates are essential for maintaining the security of your WordPress site. Regularly check for updates and ensure your site is running the latest version to protect against potential attacks.

Frequently Asked Questions

What vulnerabilities were addressed in the recent WordPress update?

The update addressed two vulnerabilities: CVE-2026-60137, an unauthenticated SQL injection, and CVE-2026-63030, which allows unauthenticated remote code execution.

Which versions of WordPress are affected by these vulnerabilities?

The affected versions include WordPress 6.8.X, 6.9.X, and 7.0.X.

What should I do to secure my WordPress site?

Ensure your site is updated to one of the patched versions: 6.8.6, 6.9.5, or 7.0.2, and verify the updates manually.

Are automatic updates enabled for vulnerable WordPress sites?

Yes, WordPress has initiated automatic updates for sites running vulnerable versions, but manual verification is still recommended.