A security flaw has been identified in the core WordPress software used by many websites hosted on our platform. This issue, called an interpretation conflict, could allow attackers to inject malicious database commands into your site, which can be used to run unauthorized, harmful code on your website without your permission.
If this flaw is exploited, bad actors could gain control of your site, access sensitive information stored on it, or alter your site’s content and normal functionality. This specific vulnerability can also be chained with another known WordPress security issue (CVE-2026-60137) to increase the potential impact of an attack.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-63030