WordPress Vulnerabilities

WordPress < 7.0.2 - REST API batch-route confusion and SQLi to RCE

Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Affects WordPress

Fixed in WordPress 7.0.2
Fixed in WordPress 7.0.2
Fixed in WordPress 6.9.5
Fixed in WordPress 6.9.5
Fixed in WordPress 6.9.5
Fixed in WordPress 6.9.5
Fixed in WordPress 6.9.5

References

Miscellaneous

Original Researcher
Adam Kues (Assetnote / Searchlight Cyber)
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 1 month ago)
Added
2026-07-20 (about 1 month ago)
Last Updated
2026-07-20 (about 1 month ago)

Other