There is a security vulnerability in standard WordPress core software. This is a type of input handling flaw (called a SQL injection vulnerability) that occurs when a plugin or theme installed on your WordPress site sends unvetted, untrusted data to a specific system parameter.
This vulnerability can be chained with a separate, known WordPress security flaw (identified as CVE-2026-63030) to allow unauthenticated attackers—people who do not have valid login credentials for your site—to execute arbitrary code on default WordPress installations. If successfully exploited, this could let attackers take full control of your site, access or steal sensitive data stored on it, or use your site to host or spread malicious content.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137