
patch your wordpress. cve-2026-63030 is a pre-auth rce via sql injection. 6.8.5 and below: not affected 6.9.0–6.9.4: affected 7.0.0–7.0.1: affected props to our friends at @assetnote for the crazy find
WordPress sites on 6.9.0-6.9.4 or 7.0.0-7.0.1 are exposed to unauthenticated RCE via SQL injection and should patch immediately; 6.8.5 and earlier are unaffected.
Checking sign-in…
Loading comments…