Remote Code Execution (RCE) Affecting johnpbloch/wordpress-core package, versions >=6.9.0, <6.9.5>=7.0.0, <7.0.2


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked
EPSS
97.27% (100th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Remote Code Execution (RCE) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-JOHNPBLOCHWORDPRESSCORE-18134060
  • published21 Jul 2026
  • disclosed16 Jul 2026
  • creditAdam Kues

Introduced: 16 Jul 2026

CVE-2026-63030  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade johnpbloch/wordpress-core to version 6.9.5, 7.0.2 or higher.

Overview

johnpbloch/wordpress-core is a web software you can use to create a website or blog.

Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to a REST API batch-route confusion weakness in the batch request endpoint, which resolves batched subrequests in a way that confuses route or permission handling. An attacker can reach remote code execution by combining this batch-endpoint route confusion with the author__not_in SQL injection in WP_Query, chaining the two to execute code on the server. Exploitation affects WordPress 6.9 and later where the batch-route behavior is present, and reaching remote code execution requires chaining with the SQL injection.

CVSS Base Scores

version 4.0
version 3.1