CVE-2026-63030

WordPress-Versionen vor 6.9.5 und 7.0.x vor 7.0.2 sind von einem Problem betroffen, bei dem es zu Verwirrungen in der Routenverarbeitung … (CVE-2026-63030)

criticalPoCEPSS 95%
Severity
critical
PoC (öffentlich gemeldet)
94.7 %
Kritisch — Modell sagt sehr hohe Ausnutzungs-Wahrscheinlichkeit in den nächsten 30 Tagen.
Veröffentlicht
2026-07-17 19:14 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-07-18 05:16 UTC· contact@wpscan.com
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  2. New CVE Received2026-07-17 20:17 UTC· contact@wpscan.com
    • Affected: WordPress
    • Description: WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
    • Reference: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
    • Reference: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
  3. CVE Modified2026-07-17 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    • CWE: CWE-436
    • SSVC: {"id":"CVE-2026-63030","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…

Beschreibung

WordPress-Versionen vor 6.9.5 und 7.0.x vor 7.0.2 sind von einem Problem betroffen, bei dem es zu Verwirrungen in der Routenverarbeitung des REST API Batch-Endpunkts kommt. Dieses Problem kann in Kombination mit einer SQL-Injektion im WP_Query (CVE-2026-60137) dazu führen, dass ein Angreifer eine SQL-Injektion durchführen und Remote Code Execution erreichen kann.

Quelle: CVELISTV5