Critical WordPress Vulnerability Chain Allows Server Takeover with a Single Anonymous Request

The WordPress development team has released emergency security updates after disclosing two core vulnerabilities that can be combined into a critical attack chain. The issue affects the vast majority of websites running recent versions of the popular content management system.

One Request Is All It Takes

According to the official security advisory, WordPress installations running versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are vulnerable. The flaws have been addressed in WordPress 6.8.6, 6.9.5, and 7.0.2.

The vulnerabilities have been assigned the identifiers CVE-2026-63030 and CVE-2026-60137. While each issue is serious on its own, together they form a complete attack chain capable of compromising an affected server.

According to the developers, an attacker can escalate from a single anonymous HTTP request to remote code execution without authentication or any interaction from the site's users. That is an unusually short attack path, even by modern cybersecurity standards.

Security Patches Are Already Available

The official security advisory was published on July 17 alongside the release of patched versions. Website owners are advised to upgrade to WordPress 6.8.6, 6.9.5, or 7.0.2, where both vulnerabilities have been resolved.

The incident serves as another reminder that delaying security updates can sometimes give attackers a much shorter schedule than website administrators would prefer.

Share This Story