Wordpress Alert: REST batch-route confusion leading to code execution (CVE-2026-63030)

An affected core version still exposes the vulnerable REST batch-route behavior. The documented route-confusion and SQL injection chain can lead to remote code execution.

What it looks like

An affected core version still exposes the vulnerable REST batch-route behavior.

Why it matters

The documented route-confusion and SQL injection chain can lead to remote code execution.

What to check

Check the July 2026 release and confirm that the applicable fixed core version is installed.

Documentation

This is a documented WordPress core vulnerability. The linked release gives the affected versions and fixes. See WordPress 7.0.2 security release.