On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by unauthenticated attackers to create an administrator account and then execute code through normal administrator capabilities, such as uploading a plugin.
The chain consists of two vulnerabilities: an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, and a REST API batch request route confusion vulnerability identified as CVE-2026-63030, which can be chained with the SQL injection to escalate the impact to unauthenticated administrator account creation.
The primary SQL Injection vulnerability affects WordPress core versions 6.8 through 6.8.5, 6.9 through
Click here to continue reading this article.
