A security flaw has been identified in WordPress core, the base software that runs all WordPress websites. This flaw is a database vulnerability called SQL injection, which lets attackers sneak harmful commands into your site's database if a plugin or theme installed on your site passes unvetted user input to a specific core parameter.
This flaw can be chained with a separate documented WordPress vulnerability (CVE-2026-63030) to let attackers who do not have any login access to your site take full control of a default WordPress installation, allowing them to run any code they choose on the affected site.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137