A security vulnerability has been identified in WordPress Core, the base software that powers all WordPress websites hosted on our platform. This flaw stems from an interpretation conflict in the WordPress codebase.
If exploited by a bad actor, this issue could allow them to launch SQL injection attacks that target your site's private database, and may also let them run unauthorized malicious code on your site. This could put your site content, user data, and overall control of your site at risk.
Security teams have confirmed this flaw can be chained with another known WordPress security vulnerability to increase the potential impact of attacks.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-63030