THREAT OPS › Threat News › PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
<p>On July 17, 2026, the <a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/" rel="noopener" target="_blank">WordPress Security Team released updates</a> to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase its impact to
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- 00000000000000000000000000000000md5
- 8ec93bb7e5ec96ab4636699e413382c9md5
- 4418c9327e7455cc20ecc3238895e0d9md5
- CVE-2026-60137cve
- CVE-2026-63030cve
- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/url
- https://www.cve.org/CVERecord?id=CVE-2026-63030url
- https://www.cve.org/CVERecord?id=CVE-2026-60137url
- www.gravatar.comdomain