WordPress Core: WordPress Core SQL Injection Vulnerability

  • Friday, 24th July, 2026
  • 04:02am

A security flaw has been identified in the core WordPress software, known as a SQL injection vulnerability. This type of bug lets attackers interfere with how your site interacts with its database, and it is triggered when a plugin or theme you have installed sends unvetted user input to a vulnerable parameter in WordPress core.

This flaw can be chained with a separate known vulnerability (CVE-2026-63030) to allow attackers who do not have login credentials for your site to run arbitrary code on default WordPress installations. If exploited, this could give an attacker full control over your site, letting them steal visitor data, host malicious content, or disrupt your site's normal operation.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137

« Back