WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 have a remote code execution flaw in the REST API batch route that is being exploited. Update to 6.9.5 or 7.0.2.
Affected component: WordPress (core)
Fixed in: 6.9.5
Known exploited: this CVE is listed in the CISA Known Exploited Vulnerabilities catalog.
PowerSEC coverage: PowerSEC detects the affected versions on every plan, and has since September 28, 2026. No PowerSEC firewall rule blocks this attack. Update to 6.9.5 or 7.0.2 (or a later release on the same branch) to remove the vulnerability.
Full advisory, including detection steps and remediation: https://powersec.io/vulnerability/cve-2026-63030