A security vulnerability has been identified in the core WordPress software used to run many websites. This is a SQL injection flaw that is triggered when a WordPress plugin or theme passes unscreened, untrusted user input to a specific core parameter.
This flaw can be chained with the separate known security issue CVE-2026-63030 to allow an attacker who does not have login credentials for your WordPress site to run harmful remote code on your installation. This risk applies even to standard, unmodified default WordPress setups with no custom changes.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137