WordPress Vulnerabilities

WordPress < 7.0.2 - REST API batch-route confusion and SQLi to RCE

Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Affects WordPress

Fixed in WordPress 7.0.2
Fixed in WordPress 7.0.2
Fixed in WordPress 6.9.5
Fixed in WordPress 6.9.5
Fixed in WordPress 6.9.5
Fixed in WordPress 6.9.5
Fixed in WordPress 6.9.5

References

Miscellaneous

Original Researcher
Adam Kues (Assetnote / Searchlight Cyber)
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 16 days ago)
Added
2026-07-20 (about 13 days ago)
Last Updated
2026-07-20 (about 13 days ago)

Other