WordPress Core: WordPress Core SQL Injection Vulnerability

  • Friday, 24th July, 2026
  • 16:02pm

A security flaw has been identified in core WordPress software. This issue, called a SQL injection vulnerability, occurs when a plugin or theme installed on your WordPress site passes unvetted visitor input to a specific site parameter.

This vulnerability can be chained with the separate known flaw CVE-2026-63030 to allow unauthenticated attackers (people without login access to your site) to run harmful, unauthorized code on default WordPress installations.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137

« Back