SiteCountry Blog
  • Home
  • About
Sign in Subscribe

REST API

Editor reviewing a WordPress core security update on a laptop while exploit traffic logs scroll in a terminal window in the

Ninety Minutes to Weaponized: Inside the WordPress Core RCE Race

A pre-auth SQL injection and a REST batch route confusion in WordPress core were chained into remote code execution. Attackers hit the internet roughly ninety minutes after the fix shipped, and the campaign has not slowed down.
SiteCountry Team Jul 27, 2026
Abstract editorial illustration of a translucent security shield blocking attack traffic around a WordPress site.

Cloudflare WAF Blocks Two Critical WordPress Vulnerabilities: What Site Owners Must Do

Cloudflare activated emergency WAF rules for a critical WordPress REST API RCE and a related SQL injection flaw. Here is what affected versions are, how the rules work, and the steps every site owner should follow.
SiteCountry Team Jul 22, 2026

Subscribe to SiteCountry Blog

Don't miss out on the latest news. Sign up now to get access to the library of members-only articles.
  • Sign up
SiteCountry Blog © 2026. Powered by Ghost