Two new high severity WordPress vulnerabilities, patch immediately!
2026-07-18T20:51:45Z•58e46c10a6a9191e93649e6383d1cd792b9a0544db7c9ea03b9780dd3bd59e27
1PasswordAES-128AI voice phishingAnthropic ClaudeCVE-2026-60137CVE-2026-63030Coca-ColaECDHFaceTime scamsFairlifeRCESQL injectionSpiralsXSPbrowser authenticationcaller ID spoofingcredential theftcross-site promptingdeepfake detection (Polygraf AI)prompt injectionransomwarerustsocial engineeringsupply-chain impactwordpress
What happened
Multiple high-impact security stories: WordPress 7.0.2 fixes one critical and one high-severity flaw (CVE-2026-60137 — facilitated SQL injection; CVE-2026-63030 — REST API batch-route confusion + SQLi leading to possible RCE); urgent patching recommended for affected 6.9 instances. A new Rust-written ransomware family dubbed “Spirals” rapidly moved from initial access to data theft and encryption in under 24 hours, using per-file AES-128 keys wrapped via attacker-controlled ECDH. Large supply-chain/operational impact ransomware hit Coca-Cola’s Fairlife, halting US milk production. Apple warns:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 58e46c10a6a9191e93649e6383d1cd792b9a0544db7c9ea03b9780dd3bd59e27
- Enrichment time
- 2026-07-18T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.