Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs

https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-2560-80.jpg
  • WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)
  • When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover
  • Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks

Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.

WordPress developers released a patch for two vulnerabilities - an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.

The former is a medium-severity, 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical-severity, 9.8/10 flaw affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 of the world’s most popular website builder.

Exploitation underway

According to The Register, these bugs...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more

https://www.itvoice.in/wp-content/uploads/2026/07/Copy-of-Redington-2026-07-29T133537.097.jpg

LOGIC Upgrades ZX Series Interactive Displays to Android 16, Delivering Smarter, Faster and More Secure Collaboration

LOGIC, the flagship visual solutions brand under Online Instruments (India) Limited, introduces the Android 16-powered ZX Series Interactive Flat Panel Display, upgraded from Android 14 to Android 16, reinforcing its commitment to delivering next-generation collaboration solutions with enhanced performance, intelligent AI capabilities, advanced security, and seamless user experiences. The ZX