NCSC-2026-0250 [1.00] [H/M] Vulnerabilities fixed in WordPress by Automattic
Two vulnerabilities have been fixed in WordPress Core 6.8.6, 6.9.5, and 7.0.2. An unauthenticated malicious actor can exploit the vulnerabilities remotely to execute arbitrary code. This requires sending a malicious HTTP request to the batch API of a WordPress site. Since vulnerabilities in content management systems structurally attract the interest of malicious actors, NCSC expects that the vulnerabilities will be exploited in the short term.
CSIRTS triage
- What
- Two vulnerabilities allow unauthenticated remote code execution via the batch API.
- Who is affected
- Deployments of WordPress Core versions 6.8.6, 6.9.5, and 7.0.2 are affected.
- Urgency
- Remediation is urgent due to the potential for exploitation by malicious actors in the short term.
- Action
- Update to the latest version of WordPress to mitigate the vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch WordPress
Get an email when a new WordPress advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0250
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation likely imminentCVE-2026-60137EPSS puts this in the most-targeted tier (79.0% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Exploitation likely imminentCVE-2026-63030EPSS puts this in the most-targeted tier (98.4% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-60137 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63030 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [critical] WordPress: Multiple vulnerabilities allow code executioncert-bund
- unknownDSA-6399-1 wordpress - security updatedebian
- unknownexploitedWordPress security advisory (AV26-723) - Update 1cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-60137: WordPress Core SQL Injection Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-63030: WordPress Core Interpretation Conflict Vulnerabilitycisa-kev
- unknownWordPress Multiple Vulnerabilitieshkcert
- unknownexploitedMultiple vulnerabilities in WordPress (July 20, 2026)cert-fr-alerte
- unknownMultiple vulnerabilities in WordPress (July 20, 2026)cert-fr-avis
- criticalexploitedCVE-2026-63030: WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint r…nvd
- mediumexploitedCVE-2026-60137: WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly san…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30