WordPress forces the update of millions of web pages due to two serious vulnerabilities in exploitation

WordPress.org has forced the update of millions of web pages to protect them from two serious vulnerabilities, of which proofs of concept have been published and which do not require any type of condition to be exploited.

Website administrators using WordPress should update to 7.0.2, especially if they are using a version later than 6.8, as they are vulnerable to two serious security flaws identified by Searchlight Cyber ​​researchers.

These are the vulnerabilities listed as CVE-2026-63030 and CVE-2026-60137, which can be combined to launch a “remote code execution without prior authentication in the WordPress core” attack, as explained in a statement. It has the potential to affect the estimated more than 500 million websites that use WordPress.

The fix is ​​available with version 7.0.2, which WordPress.org urges you to update “immediately.” However, “due to the severity of the problem”, they have forced automatic updating for web pages running the affected versions.

Although Searchlight Cyber ​​delayed publishing the technical details so that administrators had enough time to apply the fix, proofs of concept have been published on GitHub and are known to be already being exploited, as cybersecurity company watchTowr confirmed to Bleeping Computer.

By Editor