Skip to content
Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    5 Free Courses to Go From AI Beginner to Practitioner

    July 21, 2026

    VCF Upgrade Field Guide: Planning the Maintenance Move

    July 21, 2026

    Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs

    July 21, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs
    Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs
    Tech Reviews

    Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs

    gvfx00@gmail.comBy gvfx00@gmail.comJuly 21, 2026No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    • WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)
    • When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover
    • Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks

    Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.

    WordPress developers released a patch for two vulnerabilities – an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.

    The former is a medium-severity, 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical-severity, 9.8/10 flaw affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 of the world’s most popular website builder.

    Latest Videos From

    Table of Contents

    Toggle
    • Exploitation underway
      • Related posts:
    • Chaos erupts as cyberattack disrupts learning platform Canvas amid finals
    • Spotify Enters Its Fitness Era With New Peloton and Influencer Partnership
    • Sunday Night Football: How to Watch Falcons vs. 49ers Tonight

    Exploitation underway

    According to The Register, these bugs are not that dangerous when looked at separately, since they are rather difficult to exploit. However, when chained together, they allow unauthenticated threat actors to execute malicious code remotely, which means full website takeover.

    Security researchers at Knott say threat actors picked up on the scent rather quickly.


    You may like

    The patch was released on Friday, but “by the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Knott said.

    “From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.”

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    It is worth mentioning that these vulnerabilities affect WordPress directly, instead of different plugins or themes. WordPress is by far the most popular website builder platform in the world, powering more than half of all websites in existence today.

    To protect your assets, make sure to upgrade WordPress to version 6.9.5, since it contains fixes for both flaws.


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Google logo on a black background next to text reading 'Click to follow TechRadar'

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


    Related posts:

    Botnet of more than 17 million devices dismantled

    Looking to buy a new Samsung mini-LED TV for the World Cup? I tested two side-by-side and it's an 'o...

    Two Windows vulnerabilities, one a 0-day, are under active exploitation

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGame Pass Was A Good Idea But It Didn’t Work, Forza Horizon 5 Creative Director Says
    Next Article VCF Upgrade Field Guide: Planning the Maintenance Move
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Fusion 2.5G Gateway Review: TP-Link’s Formidable Non-Wi-Fi Router

    July 21, 2026
    Tech Reviews

    Windows 0-day drops the same day Microsoft releases record number of patches

    July 21, 2026
    Tech Reviews

    Netflix Brings ASL Interpretations To Dozens Of Shows And Movies For Kids

    July 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025212 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025134 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 2025100 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025212 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025134 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 2025100 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.