THREATOPS
THREAT OPSThreat News › PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain

PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain

medwordfencePublished 2026-07-17

<p>On July 17, 2026, the <a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/" rel="noopener" target="_blank">WordPress Security Team released updates</a> to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase its impact to

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/07/psa-wordpress-core-patched-unauthenticated-remote-code-execution-vulnerability-chain/