WordPress security advisory (AV26-723) - Update 1

Serial number: AV26-723
Date: July 20, 2026
Date: July 21, 2026

On July 17, 2026, WordPress published a security advisory to address vulnerabilities in the following product:

  • WordPress 7.0 – versions prior to 7.0.2
  • WordPress 6.9 – versions prior to 6.9.5
  • WordPress 6.8 – versions prior to 6.8.6
  • WordPress 7.1 beta – versions prior to 7.1 beta2

Open-source reporting indicates that CVE-2026-60137 and CVE-2026-63030 are being exploited in the wild.

Update 1

On July 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60137 and CVE-2026-63030 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

Date modified: