A security flaw has been identified in core WordPress software. This is a SQL injection vulnerability, which occurs when a plugin or theme installed on your WordPress site passes untrusted, unvetted input to a specific parameter built into WordPress core.
This flaw can be combined with a separate, known security issue to allow attackers who do not have login credentials for your site to run arbitrary code on default WordPress installations. Gaining this level of access could let an attacker take control of your site, steal sensitive visitor or site data, or alter your site's content and functionality.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137