A security flaw has been found in the core WordPress software that powers a large number of websites. This issue, known as an interpretation conflict, exists in unpatched versions of the WordPress platform.
If an attacker exploits this flaw, they could inject harmful commands into your site's database, which may lead to full remote control of your website. This vulnerability can also be chained with another existing WordPress security issue to increase its potential impact.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-63030