Vulnerability
Published 2026-07-21
Verified 2026-09-19

WordPress Core (CVE-2026-63030)

WordPress Core Interpretation Conflict Vulnerability. WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

Product
WordPress Core
Exploited in Australia?
unknown

Primary: NVD · Vendor: CISA KEV · CVE: CVE-2026-63030, CVE-2026-60137

vulnerabilities