20-07-2026 – Urgent check your WordPress version now wp2shell CVE-2026-60137 CVE-2026-63030
What has happened On 17 July 2026 the WordPress security team released an emergency update fixing two flaws that can be chained together: CVE-2026-60137 – a SQL injection flaw in the author__not_in parameter of WP_Query. CVE-2026-63030 – a REST API batch-route confusion flaw introduced in WordPress 6.9. Individually they are…