An urgent security update is available for WordPress 6.9.x and 7.0.x. CVE-2026-63030 is included in CISA's current catalog of known exploited vulnerabilities. Affected installations should move to a fixed version immediately.
Is your WordPress version affected?
The affected releases are WordPress 6.9.x before 6.9.5 and WordPress 7.0.x before 7.0.2. This includes WooCommerce sites running on one of those WordPress Core versions.
The issue is fixed in versions 6.9.5 and 7.0.2. Later versions also include the correction.
What to do now
Update WordPress immediately to 6.9.5, 7.0.2, or a later version in the appropriate release line. WordPress.org enabled forced updates for affected versions.
Even so, check the version currently active on your site. That is the only way to confirm the security update completed successfully.
Why this update is urgent
CISA lists CVE-2026-63030 in its current Known Exploited Vulnerabilities catalog. This confirms that attackers are exploiting the vulnerability in the wild.
The documented vulnerability chain combines route confusion in the REST API batch endpoint with CVE-2026-60137. It can make SQL injection and remote code execution possible.
Check logs if you suspect exploitation
If you suspect exploitation, also review your logs and verify the integrity of the site. Updating closes the known vulnerability, but it does not replace an investigation into earlier activity.
The WordPress release notice is the primary source. The MITRE CVE record confirms affected and fixed versions, while the CISA catalog establishes active exploitation.