WordPress exploit chain created an administrator
An unfamiliar payload resembling CVE-2026-63030 and CVE-2026-60137 manipulated WordPress's nested batch handling and fabricated cached posts to create an administrator. The chain slipped past the site's WAF. Aiko removed the account and blocked further attempts.









