A security flaw has been found in WordPress core that can be triggered when a theme or plugin installed on your site passes unscreened, untrusted user input to a specific core setting. This is a SQL injection vulnerability, a type of flaw that allows bad actors to run unauthorized commands on your site’s internal database.
When combined with a separate known WordPress vulnerability, this flaw can be exploited by attackers who do not even have login access to your site to take full remote control of default WordPress installations. This lets them run any code of their choosing on your site’s server.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137