A security flaw has been identified in standard WordPress core software. This flaw can trigger a SQL injection attack if any plugin or theme installed on your site sends untrusted, unvetted data to a specific site parameter. SQL injection is a type of attack that lets bad actors access or tamper with the database your WordPress site uses to store content, user information, and site settings.
This flaw can be chained with another known WordPress vulnerability to let attackers who do not have login credentials for your site run arbitrary code on your site’s hosting environment. For default WordPress installations, this could allow bad actors to modify your site content, steal sensitive data, or take full control of your site without your knowledge.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137