Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs
WordPress patches two flaws: CVE‑2026‑60137 SQL injection, medium severity and CVE‑2026‑63030 REST API batch‑route confusion, critical severity When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover Admins should urgently upgrade to WordPress 6.9.5 or newe… …