A security flaw has been found in standard WordPress core software, the base system that powers all basic WordPress websites. This is a SQL injection vulnerability that can be triggered when a WordPress plugin or theme you have installed passes unvetted, untrusted user input to a specific core parameter.
This vulnerability can be combined with a separate known WordPress flaw (CVE-2026-63030). When chained together, these issues allow an attacker with no login access to your site to run unauthorized code on servers running default WordPress installations. This could let bad actors modify your website content, access sensitive data stored on your site, or use your site to spread harmful material.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-60137