WordPress Core: WordPress Core SQL Injection Vulnerability

  • Tuesday, 21st July, 2026
  • 22:01pm

We are sharing information about a security flaw identified in WordPress Core. This is a SQL injection vulnerability that occurs when a plugin or theme installed on your site passes unvetted, untrusted user input to a specific site parameter. This flaw can be combined with a separate, already known WordPress vulnerability to let unauthenticated attackers (people who do not have login credentials for your site) run unauthorized commands on default WordPress installations. For site owners, this means an attacker could gain full control of your site without needing to log in at all.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137

« Back