A SQL injection security flaw exists in WordPress core. This vulnerability is triggered when a plugin or theme you have installed passes untrusted, unvetted input to a specific site parameter. This flaw can be chained with the separate known vulnerability CVE-2026-63030 to allow attackers with no login access to your site to run their own code on default WordPress installations, which can lead to full site compromise.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137