WordPress Core: WordPress Core SQL Injection Vulnerability

  • Thursday, 23rd July, 2026
  • 22:02pm

A security flaw has been found in the core WordPress software used to run many websites. This is a SQL injection vulnerability, a type of security issue that lets bad actors interfere with your site’s database — the system that stores all your posts, user information, site settings, and other core content — when specific conditions are met.

The flaw is triggered if a plugin or theme you have installed on your WordPress site passes unscreened, untrusted user input to a specific system parameter. What makes this risk especially severe is that attackers can chain this flaw with another known WordPress vulnerability to run malicious code on your site, even without logging into your WordPress admin area. On standard default WordPress installations, this could let attackers take full control of your site, steal sensitive data, or harm visitors who access your pages.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137

« Back