All security updates were rolled out on all Boxes as planned yesterday evening by 8 PM. _____ Alle Sicherheitsupdates sind wie geplant gestern Abend bis 20 Uhr auf allen Boxen aufgespielt worden.
Posted Jul 19, 2026 - 07:30 CEST
Monitoring
Security researchers have found two vulnerabilities in WordPress core that can be chained into an exploit, allowing code to be injected without prior authentication. Specifically, it involves a critical SQL injection (CVE-2026-60137, CVSS 9.1) combined with a flaw in the REST API (wp2shell, CVE-2026-63030, CVSS 7.5). WordPress 6.9 and 7.0 are affected, with the SQL injection also affecting WordPress 6.8. We are not aware of any active exploitation at this time.
We'll roll out the security updates on all Boxes today – this process will be completed by the end of the day.
____________
Sicherheitsforscher haben zwei Sicherheitslücken in WordPress Core gefunden, die sich zu einem Exploit verketten lassen und dann das Einschleusen von Schadcode ohne vorherige Anmeldung ermöglichen. Betroffen ist bereits die reine Standard-Installation, ohne zusätzliche Plugins. Im Detail handelt es sich um eine kritische SQL-Injection (CVE-2026-60137, CVSS 9,1) in Verbindung mit einem Fehler im REST-API (wp2shell, CVE-2026-63030, CVSS 7,5). Betroffen sind WordPress 6.9 und 7.0, die SQL-Injection zusätzlich WordPress 6.8. Das WordPress-Team hat die Sicherheitsreleases 6.8.6, 6.9.5 und 7.0.2 veröffentlicht. Aktive Angriffe sind uns zum aktuellen Zeitpunkt nicht bekannt.
Wir werden die Sicherheitsupdates noch heute auf allen Boxen ausrollen – dieser Prozess wird zum Ende des Tages erledigt sein.