Vulnerability Details CVE-2026-63030
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.089
EPSS Ranking 94.7%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Ransomware Campaign
Unknown
Products affected by CVE-2026-63030
-
cpe:2.3:a:wordpress:wordpress:6.9
-
cpe:2.3:a:wordpress:wordpress:6.9.1
-
cpe:2.3:a:wordpress:wordpress:6.9.2
-
cpe:2.3:a:wordpress:wordpress:6.9.3
-
cpe:2.3:a:wordpress:wordpress:6.9.4
-
cpe:2.3:a:wordpress:wordpress:7.0
-
cpe:2.3:a:wordpress:wordpress:7.0.1