Wordpress Alert: REST batch-route confusion leading to code execution (CVE-2026-63030)
An affected core version still exposes the vulnerable REST batch-route behavior. The documented route-confusion and SQL injection chain can lead to remote code execution.