Last updated on July 21, 2026 at 05:43 pm

We’re aware of two security vulnerabilities (CVE-2026-63030 and CVE-2026-60137) affecting WordPress websites.

If exploited together, these vulnerabilities could allow an unauthenticated attacker to perform SQL injection and potentially gain remote code execution (RCE) on an affected WordPress website.

The affected versions are:

  • WordPress 6.9.0 to 6.9.4
  • WordPress 7.0.0 to 7.0.1
  • WordPress 7.1 beta

What you need to do

If your school website uses WordPress, we recommend checking which version you’re running and ensuring it’s updated to the latest available secure release.

Website administrators should also ensure that WordPress plugins and themes are kept up to date.

Please refer to this WordPress advisory for more information, including on recommended actions.

If you’re unsure whether your school website is impacted, please contact your website administrator or IT contact.