CVE-2026-63030
WordPress-Versionen vor 6.9.5 und 7.0.x vor 7.0.2 sind von einem Problem betroffen, bei dem es zu Verwirrungen in der Routenverarbeitung … (CVE-2026-63030)
Severity
critical
79.00
PoC (öffentlich gemeldet)
9.8
94.7 %
Kritisch — Modell sagt sehr hohe Ausnutzungs-Wahrscheinlichkeit in den nächsten 30 Tagen.
Veröffentlicht
2026-07-17 19:14 UTC
—
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-07-18 05:16 UTC· contact@wpscan.com
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- New CVE Received2026-07-17 20:17 UTC· contact@wpscan.com
- Affected: WordPress
- Description: WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
- Reference: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
- Reference: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
- CVE Modified2026-07-17 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CWE: CWE-436
- SSVC: {"id":"CVE-2026-63030","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
Beschreibung
WordPress-Versionen vor 6.9.5 und 7.0.x vor 7.0.2 sind von einem Problem betroffen, bei dem es zu Verwirrungen in der Routenverarbeitung des REST API Batch-Endpunkts kommt. Dieses Problem kann in Kombination mit einer SQL-Injektion im WP_Query (CVE-2026-60137) dazu führen, dass ein Angreifer eine SQL-Injektion durchführen und Remote Code Execution erreichen kann.
Quelle: CVELISTV5