Two recently disclosed vulnerabilities have drawn significant attention across the security community, including a critical unauthenticated remote code execution (RCE) vulnerability and a related SQL injection vulnerability.
To help protect customers while they update their WordPress installations, Bunny Shield now includes new WAF protections for both CVEs, blocking known exploitation attempts before they reach your origin.
These protections help reduce your exposure, but they are not a substitute for patching. WordPress has released security updates for the affected versions, and updating your installation should remain your highest priority.
Affected versions
WordPress has released fixes in the following versions:
- 7.0.2
- 6.9.5
- 6.8.6
- 7.1 Beta 2
Versions earlier than 6.8 are not affected.
The WordPress project is treating these vulnerabilities with the highest priority and is automatically deploying updates to supported installations wherever possible. Even so, it's worth confirming that your sites have successfully updated and are running a patched release.
Understanding the vulnerabilities
The advisory includes two related vulnerabilities affecting different parts of WordPress.
CVE-2026-60137 - SQL Injection
This vulnerability affects WordPress 6.8 and later and allows specially crafted input to manipulate database queries.
Severity: High
CVE-2026-63030 - Unauthenticated Remote Code Execution
This vulnerability affects WordPress 6.9 and later. Under specific conditions, if a persistent object cache is not enabled, an attacker can execute arbitrary code through the WordPress REST API batch endpoint without authentication.
No login or user interaction is required to exploit this vulnerability.
Severity: Critical
Because the RCE vulnerability builds on the SQL injection vulnerability, the available fixes differ slightly between versions:
- 6.8.6 fixes the SQL injection vulnerability
- 6.9.5, 7.0.2, and 7.1 Beta 2 address both vulnerabilities
How Bunny Shield protects your site
Bunny Shield now includes dedicated managed WAF rules for both CVEs.
While our existing WAF engine already detected many exploit attempts targeting these CVEs, we've added dedicated managed rules to improve detection accuracy and provide more precise protection against the disclosed attack paths.
These rules inspect incoming requests before they reach your WordPress installation, identifying and blocking known exploit attempts targeting both vulnerabilities.
If your website is already protected by Bunny Shield, no additional configuration is required.
Protection while you update
Security updates are always the permanent fix, but deploying them isn't always instantaneous. Large WordPress fleets, maintenance windows, compatibility testing, and operational requirements can all delay updates, leaving a window of opportunity for attackers.
Bunny Shield helps close that gap by identifying and blocking malicious requests at the edge before they ever reach your application. This provides an additional layer of protection against publicly known exploit techniques while you complete your update rollout.
This approach, often referred to as virtual patching, reduces the risk of exploitation during the period between a vulnerability being disclosed and every affected system being updated. It complements software updates, but never replaces them.
What you should do
If you manage WordPress sites, we recommend taking the following steps:
- Update to a patched version of WordPress as soon as possible.
- Verify that Bunny Shield is enabled for your website.
- Review your security logs for blocked requests related to these vulnerabilities
- Continue monitoring WordPress security advisories for any additional guidance.
Staying ahead of new attack techniques
Public vulnerability disclosures are often followed by new proof-of-concept exploits and variations that attempt to bypass existing detections. As those techniques evolve, so do our protections.
We'll continue monitoring these vulnerabilities and updating Bunny Shield's managed protections as new attack techniques emerge, helping keep your applications protected as the threat landscape evolves.
Protect your sites with Bunny Shield
While keeping WordPress up to date is your best defense, Bunny Shield adds an extra layer of protection by blocking known exploit attempts before they reach your origin.
If you're already using Bunny Shield, these managed protections are available automatically. If you're not, you can get started in minutes and protect your applications against WordPress vulnerabilities, bots, DDoS attacks, and a wide range of web threats.
Enable Bunny Shield today to protect your WordPress sites against emerging threats, bots, DDoS attacks, and other common web attacks. Log in to your bunny.net account, or sign up today to start shielding your websites.

