WordPress: 2 Actively-Exploited Flaws Added to CISA KEV
CISA has added two actively-exploited WordPress vulnerabilities to its Known Exploited Vulnerabilities Catalog, urging immediate action from federal agencies and other organizations to mitigate these critical security risks.

Key findings
- CISA added two WordPress vulnerabilities to its KEV catalog on July 21, 2026.
- Both flaws, CVE-2026-60137 and CVE-2026-63030, are confirmed to be actively exploited in the wild.
- Organizations using WordPress must apply available patches immediately to prevent exploitation.
- Federal agencies have until January 21, 2027, to remediate these vulnerabilities.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert, adding two WordPress vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. This action confirms that these flaws are under active exploitation in the wild, posing significant threats to organizations utilizing the popular content management system. The inclusion in the KEV catalog serves as a federal directive for agencies to remediate these vulnerabilities promptly, highlighting the severe risk they present.
The newly added vulnerabilities are:
- **CVE-2026-60137**: This flaw affects Debian WordPress versions 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, indicating a critical security bypass or similar issue that attackers are leveraging.
- **CVE-2026-63030**: Impacting Debian WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2, this vulnerability is associated with a REST API bypass, which could allow unauthorized access or control over affected WordPress installations.
Neither of these actively exploited vulnerabilities has been publicly associated with ransomware campaigns at this time. However, their active exploitation status alone underscores the urgency of applying available security updates to prevent potential data breaches, website defacement, or other malicious activities.
All organizations running WordPress installations are strongly advised to review their systems and apply the necessary patches without delay. For federal civilian executive branch agencies, CISA's Binding Operational Directive (BOD) 22-01 mandates that these vulnerabilities be remediated by January 21, 2027. However, given the confirmed active exploitation, all entities should prioritize patching immediately, regardless of their federal status, to protect against ongoing threats.