Two new high severity WordPress vulnerabilities, patch immediately!

2026-07-18T20:51:45Z58e46c10a6a9191e93649e6383d1cd792b9a0544db7c9ea03b9780dd3bd59e27
1PasswordAES-128AI voice phishingAnthropic ClaudeCVE-2026-60137CVE-2026-63030Coca-ColaECDHFaceTime scamsFairlifeRCESQL injectionSpiralsXSPbrowser authenticationcaller ID spoofingcredential theftcross-site promptingdeepfake detection (Polygraf AI)prompt injectionransomwarerustsocial engineeringsupply-chain impactwordpress

What happened

Multiple high-impact security stories: WordPress 7.0.2 fixes one critical and one high-severity flaw (CVE-2026-60137 — facilitated SQL injection; CVE-2026-63030 — REST API batch-route confusion + SQLi leading to possible RCE); urgent patching recommended for affected 6.9 instances. A new Rust-written ransomware family dubbed “Spirals” rapidly moved from initial access to data theft and encryption in under 24 hours, using per-file AES-128 keys wrapped via attacker-controlled ECDH. Large supply-chain/operational impact ransomware hit Coca-Cola’s Fairlife, halting US milk production. Apple warns:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
58e46c10a6a9191e93649e6383d1cd792b9a0544db7c9ea03b9780dd3bd59e27
Enrichment time
2026-07-18T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.