Summary
Experts warn that millions of WordPress websites are at risk due to two recently patched vulnerabilities, CVE-2026-60137 and CVE-2026-63030, which, when chained, allow unauthenticated remote code execution and full site takeover. Admins are urged to upgrade to WordPress 6.9.5 or newer immediately.