WordPress Vulnerabilities
WordPress < 7.0.2 - REST API batch-route confusion and SQLi to RCE
Description
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Affects WordPress
References
Miscellaneous
Original Researcher
Adam Kues (Assetnote / Searchlight Cyber)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-17 (about 16 days ago)
Added
2026-07-20 (about 13 days ago)
Last Updated
2026-07-20 (about 13 days ago)