Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN766
_____________________________________________________________________


DATE                : 20/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running WordPress versions prior to
                                  6.8.6, 6.9.5, 7.0.2.
 
=====================================================================
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
_____________________________________________________________________


REST API batch-route confusion and SQL injection issue leading to
Remote Code Execution

Critical
johnbillion published GHSA-ff9f-jf42-662q 

Package
WordPress (WordPress)

Affected versions
6.9.0 - 6.9.4
7.0.0 - 7.0.1

Patched versions
6.9.5
7.0.2


Description

WordPress versions 6.9 and higher are vulnerable to a REST API
batch-route confusion weakness, which combined with an SQL
injection issue (GHSA-fpp7-x2x2-2mjf) leads to Remote Code
Execution.

WordPress versions 7.0.2, 6.9.5, and 7.1 beta2 have been released,
containing fixes for the vulnerability.

Due to the severity of the vulnerability it is recommended that
you update your sites immediately.

Discovered and responsibly disclosed by Adam Kues at
Assetnote / Searchlight Cyber.


Severity
Critical

CVE ID
CVE-2026-63030

Weaknesses
No CWEs

_____________________________________________________________________


Facilitated SQL injection vulnerability in the `author__not_in`
parameter of `WP_Query`

Moderate
johnbillion published GHSA-fpp7-x2x2-2mjf

Package
WordPress (WordPress)

Affected versions
6.8.0 - 6.8.5
6.9.0 - 6.9.4
7.0.0 - 7.0.1

Patched versions
6.8.6
6.9.5
7.0.2


Description

WordPress versions 6.8 and higher are vulnerable to an SQL injection
issue.

In WordPress versions 6.9 and higher, this combined with a 
REST API batch-route confusion issue (GHSA-ff9f-jf42-662q) leads
to Remote Code Execution.

WordPress versions 7.0.2, 6.9.5, 6.8.6, and 7.1 beta2 have been 
released, containing fixes for the vulnerability.

Due to the severity of the vulnerability it is recommended that you
update your sites immediately.

Discovered and responsibly disclosed as a team by TF1T, dtro, and
haongo.


Severity
Moderate

CVE ID
CVE-2026-60137

Weaknesses
No CWEs

_____________________________________________________________________

WordPress 7.0.2 is now available.

The 7.0.2 security release addresses one critical and one high
severity security issue.

Because this is a security release, it is recommended that you update
your sites immediately. Due to the severity, the WordPress.org team
have enabled forced updates via the auto-update system for sites
running affected versions.

To manually update you can visit your WordPress Dashboard, click
“Updates”, and then click “Update Now”, or you can download WordPress
7.0.2 from WordPress.org. On sites that support automatic background
updates, the update process will begin automatically.


Security updates included in this release

The security team would like to thank the following people for
responsibly reporting vulnerabilities and allowing them to be fixed
in this release:

    A facilitated SQL injection issue reported as a team by TF1T,
dtro, and haongo
    A REST API batch-route confusion and SQL injection issue leading
to Remote Code Execution reported by Adam Kues at
Assetnote / Searchlight Cyber

For more information on this release, please visit the HelpHub site.


Backports

    WordPress 6.9 is affected by both vulnerabilities. Version 6.9.5
has been released containing fixes for both.
    WordPress 6.8 is only affected by the first vulnerability. Version
6.8.6 has been released containing a fix.
    The beta release of WordPress 7.1 is affected by both vulnerabilities.
Version 7.1 beta2 has been released containing fixes for both.
    Versions of WordPress prior to 6.8 are not affected.

CVE and GHSA references

    CVE-2026-60137 / GHSA-fpp7-x2x2-2mjf
    CVE-2026-63030 / GHSA-ff9f-jf42-662q

Thank you to these WordPress contributors

This release was led by John Blackbourn and Barry Abrahamson. In
addition to the security researchers mentioned above, WordPress
7.0.2 would not have been possible without the significant
contributions of the following people: Aaron Jorbin, Alex Concha,
annezazu, Barry, David Baumwald, Dominik Schilling, Ehtisham Siddiqui,
Joe Dolson, Joe Hoyle, John Blackbourn, Jonathan Desrosiers,
Marius L. J., Matt Mullenweg, Mohammad Jangda, Peter Wilson, Sergey
Biryukov, vortfu, Weston Ruter, plus representatives from Altis,
Automattic, Bluehost, Cloudflare, GoDaddy, Hostinger, and WP Engine.

=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




