← Back
CVE-2026-63030
CISA KEV
critical
CVSS 9.8
WordPress Core — WordPress Core Interpretation Conflict Vulnerability
Summary
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
AI summary openai / gpt-4o
A critical security issue has been identified in certain versions of WordPress. This issue involves a misunderstanding of a particular REST API feature, allowing attackers unauthorized access to the database. In the worst case, this could lead to remote server control. If your site uses WordPress, it's imperative to apply security updates immediately. This sort of issue is similar in impact to past SQL injection attacks.
A misunderstanding in the REST API batch route in WordPress versions 6.9.x and 7.0.x allows for SQL Injection (CVE-2026-60137) potentially leading to remote code execution. The endpoint confusion enables attackers to exploit the author__not_in parameter in WP_Query. Patches are available in versions 6.9.5 and 7.0.2. Affected versions are WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 and updating immediately can protect against this vulnerability.
❓ What is the problem
WordPress CoreのREST APIにおけるエンドポイント混乱問題により、SQLインジェクションを引き起こしリモートコード実行が可能。
📍 Affected scope
WordPress 6.9.0-6.9.4および7.0.0-7.0.1のREST APIバッチエンドポイント。
🔥 Severity
リモートからの攻撃可能性大、認証不要、被害者操作不要。
🔧 How to fix
WordPressをバージョン6.9.5または7.0.2にアップデートする。
🛡️ Workaround
素材から特定できず
🔍 Detection
素材から特定できず
Related past incidents Similar incidents extracted from past CVEs
WordPressのWP_Queryのauthor__not_inパラメータに起因するSQLインジェクション脆弱性。
過去のSQLインジェクション攻撃事例で、攻撃者がデータベースに不正アクセス。
リモートコード実行が可能となる、Log4jに関する深刻な脆弱性。
If this happens at your company Expected impact per business scenario
📌 ECサイトの場合法
攻撃者により顧客情報や注文情報が不正アクセスされる可能性。
📌 社内システムの場合法
社内データベースに不正アクセスがあり、重要な営業情報が漏洩する可能性。
📌 クラウドサービス提供企業の場合法
サーバーが乗っ取られ、提供中のサービスが停止するリスク。
Recommended action
WordPressの最新版へ直ちにアップデートし、既存のセキュリティ設定を確認すること。
References
- advisory NVD
- patch [email protected]
- web [email protected]
- web 134c704f-9b21-4f2e-91b3-4a467353bcc0