Pakistan’s websites are under siege. The National Cyber Emergency Response Team issued a critical advisory warning that WordPress vulnerabilities Pakistan hackers are actively exploiting right now. Therefore, website administrators nationwide must act immediately to prevent complete system takeover.
Two severe flaws chain together to create devastating attacks. CVE-2026-63030 affects the WordPress REST API. Meanwhile, CVE-2026-60137 exploits SQL injection in the WP_Query class. Moreover, combining these vulnerabilities bypasses login requirements entirely. Consequently, hackers gain complete control without credentials.
National CERT assigned CVSS severity scores of 9.8 and 9.1 to these flaws. The highest possible rating is 10.0. Therefore, these represent near-maximum danger levels. Additionally, proof-of-concept exploit code is publicly available. Furthermore, National CERT detected active exploitation attempts within hours of disclosure.
Multiple WordPress versions are vulnerable. WordPress Core 6.9.0 through 7.0.1 faces compromise. Meanwhile, versions 6.8.x and later require urgent attention. Therefore, most current WordPress installations need immediate patching. Moreover, administrators cannot assume safety through older versions.
Government portals face extreme risk. Critical infrastructure systems remain vulnerable. Financial institutions could lose customer data. Enterprise websites risk lateral movement attacks across entire networks. Public hosting environments prove especially attractive targets. Therefore, high-value systems require immediate protection.
Successful attacks deliver catastrophic consequences. Complete website compromise happens instantly. Hackers steal sensitive data unopposed. Persistent web shells grant permanent access. Online services suffer disruption. Reputational damage becomes unavoidable. Furthermore, compromised servers serve as launching points for broader network attacks.
National CERT issued comprehensive remediation guidance. Organizations must update WordPress Core immediately to patched versions. Additionally, administrators should verify current WordPress versions across all systems. Meanwhile, plugins and themes require updates too. Furthermore, unauthenticated REST API access needs restriction. Web Application Firewalls provide temporary protection for systems unable to patch immediately.
Post-compromise actions matter equally to prevention. Server inspections must identify unauthorized PHP files. Administrator credentials require rotation after patching. WordPress core file integrity checks ensure no modifications occurred. Continuous server log monitoring reveals suspicious activity. Potentially compromised systems should be isolated. Finally, confirmed incidents must be reported through National CERT’s mechanism.
Time is critical here. Hackers actively exploit these vulnerabilities daily. Delays increase compromise likelihood exponentially. Therefore, immediate action protects both data and reputation. Finally, National CERT stressed that continuous monitoring remains essential even after patching.








