THREATOPS
THREAT OPSCVEs › CVE-2026-60137

CVE-2026-60137 — WordPress Core SQL Injection Vulnerability

CISA KEVExploited: confirmedWordPress

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

Vulnerability details

Related reporting