漏洞描述
WordPress core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are vulnerable to a pre-authentication timing-based blind SQL injection via the REST API batch endpoint. A route confusion vulnerability (CVE-2026-63030) allows nested batch requests to bypass authentication checks, while a SQL injection flaw (CVE-2026-60137) in the author_exclude parameter of /wp/v2/categories allows arbitrary SQL queries via a SLEEP-based timing oracle. An unauthenticated attacker can extract the full database contents including user credentials.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q↗github.comhttps://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf↗slcyber.iohttps://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core↗www.aikido.devhttps://www.aikido.dev/blog/unauthenticated-rce-in-wordpress-wp2shell↗wordpress.orghttps://wordpress.org/news/2026/07/wordpress-7-0-2-release/↗