WordPress Core: WordPress Core SQL Injection Vulnerability

  • Tuesday, 21st July, 2026
  • 16:01pm

A security vulnerability has been discovered in the core WordPress software that powers a large number of websites. This is a SQL injection flaw, which occurs when unfiltered, untrusted input is passed to a specific system parameter, typically when a WordPress plugin or theme sends that unvetted input to the core WordPress system.

This flaw can be chained with a separate known WordPress security issue to allow attackers who do not have any authorized access to your website to run malicious code on your site's server. This risk impacts standard, default WordPress installations that have not been modified from their original setup.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137

« Back