THREATOPS
THREAT OPSThreat News › CVE-2026-60137 / CVE-2026-63030 | WordPress Core SQL Injection and Pre-Authentication Remote Code Execution Vulnerabilities

CVE-2026-60137 / CVE-2026-63030 | WordPress Core SQL Injection and Pre-Authentication Remote Code Execution Vulnerabilities

lowhorizon3Published 2026-07-20

<p>WordPress Core contains two vulnerabilities that can be chained together to enable unauthenticated remote code execution on default WordPress installations. CVE-2026-60137 is a SQL injection vulnerability in that improperly sanitizes the parameter, while CVE-2026-63030 is a REST API batch endpoint route confusion vulnerability. Individually, CVE-2026-60137 has a CVSS score of 5.9 (Medium)…</p>

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-60137-cve-2026-63030/