Security researchers at Searchlight Cyber disclose two critical vulnerabilities in WordPress Core that together enable unauthenticated remote code execution on default installations. Tracked as CVE-2026-63030 and CVE-2026-60137, the flaws affect WordPress versions 6.9.x and 7.0.x. The first vulnerability involves a REST API batch-route confusion issue, while