notes
1. Executive summary
The "wp2shell" exploit chain combines two vulnerabilities in WordPress Core — CVE-2026-60137 (CVSS 5.9 MEDIUM, SQL Injection) and CVE-
notes
1. Executive summary
WordPress Core is affected by a critical interpretation conflict vulnerability (CVE-2026-63030, CVSS 9.8 CRITICAL) in the REST API batch endpoint,
notes
1. Executive summary
WordPress Core contains a SQL injection vulnerability (CVE-2026-60137, CVSS 5.9 MEDIUM) in the author__not_in parameter of WP_Query,
notes
1. Executive summary
WordPress Core versions 6.8 through 7.0.1 are affected by two vulnerabilities patched in the 7.0.2 security release: CVE-