Vulnerability
Published 2026-07-21
Verified 2026-09-19

WordPress Core (CVE-2026-60137)

WordPress Core SQL Injection Vulnerability. WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

Product
WordPress Core
Exploited in Australia?
unknown

Primary: NVD · Vendor: CISA KEV · CVE: CVE-2026-60137, CVE-2026-63030

vulnerabilities