Defensive self-check · CISA KEV 2026-07-21
WordPress core CVE-2026-60137 and CVE-2026-63030: version self-check
CISA added both issues to the Known Exploited Vulnerabilities catalog on 2026-07-21. WordPress shipped the fix on 2026-07-17 in the 7.0.2 release. This page tells you which version to compare and which records to review on a site you own. It does not describe how to exploit either issue.
Fixed versions
- 7.0 is fixed in 7.0.2. The 7.1 beta is fixed in 7.1 beta2.
- 6.9 is fixed in 6.9.5. Both issues affect this line.
- 6.8 is fixed in 6.8.6. WordPress says this line is affected by the first issue only.
- Older than 6.8 is not affected, according to the WordPress release note.
Check these three things
- Core version. In wp-admin open Dashboard → Updates, or read the version in
wp-includes/version.php. It should be 7.0.2, 6.9.5, 6.8.6, or a newer release on that line. - Users. Open Users → Administrator and compare the list with the people who should have access. Look for accounts created after 2026-07-17.
- Files and plugins. Note PHP files and plugin folders that appeared after 2026-07-17 and were not part of an update you ran.
What to do
Update WordPress core from wp-admin or your host's panel before you keep investigating. If the version was behind the fix, keep the site on the patched release and review the user and file lists above. Use the WordPress check for a public readme pass, then confirm the core version on the server itself.
Vendor records: WordPress 7.0.2 release note and the CISA KEV catalog, entries CVE-2026-60137 and CVE-2026-63030.