Security Advisories

Guide tag · 3 matching pages

Wordpress Alert: REST batch-route confusion leading to code execution (CVE-2026-63030)

An affected core version still exposes the vulnerable REST batch-route behavior. The documented route-confusion and SQL injection chain can lead to remote code execution.

Wordpress Alert: Page-template local file inclusion (CVE-2026-87902)

An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included. Under those conditions, unauthenticated code execution may follow.

Wordpress Alert: Core facilitated SQL injection (CVE-2026-60137)

An affected WordPress version remains unpatched after the July 2026 security release. The documented flaw can let an attacker influence a database query under the advisory's conditions.