Important correction: The previous article's CVE identifier, WordPress 7.0.4 claim, and Imagick/Ghostscript RCE claim were not supported by the cited page or WordPress's official releases. The cited news page was unrelated to WordPress. Those claims are withdrawn.
What WordPress officially released
WordPress 7.0.2 was released on July 17, 2026. CVE-2026-60137 is facilitated SQL injection through WP_Query's author__not_in argument. CVE-2026-63030 is REST API batch-route confusion and SQL injection leading to remote code execution. The earlier correction incorrectly described these as stored XSS and post-title information disclosure; those descriptions are also withdrawn.
Affected branches and action
The 6.9 and 7.0 branches are affected by both issues, fixed in 6.9.5 and 7.0.2. The 6.8 branch is affected only by CVE-2026-60137, fixed in 6.8.6. The 7.1 beta is fixed in beta2. Versions before 6.8 are unaffected by these two issues, not necessarily safe from other flaws. Check the installed branch and support policy, back up, and install an applicable fixed release.
- ✓Check the installed core version in Dashboard > Updates or with WP-CLI
- ✓Back up files and the database
- ✓Install the appropriate fixed branch or later
- ✓Review Contributor-or-higher accounts and unexpected content changes
- ✓Check the current version in the dashboard update page or WP-CLI
- ✓Back up files and the database and install an applicable fixed release
- ✓Test the dashboard, editing, themes, and essential plugins after updating
- ✓Investigate unexpected administrators, file changes, and access logs; contact the provider if compromise is suspected
