WordPress Core SQL Injection Vulnerability
July 31, 2026 · CISA · Severity: CRITICAL
WordPress Core has been identified as containing a SQL injection vulnerability (CVE-2026-60137) that occurs when plugins or themes pass untrusted input to specific parameters. This flaw can be exploited in conjunction with another vulnerability, CVE-2026-63030, enabling unauthenticated attackers to achieve remote code execution on default WordPress installations. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on July 21, 2026, noting that it is actively being exploited in the wild. The vulnerability poses a significant risk to millions of WordPress websites globally, as it allows attackers to execute arbitrary code, potentially leading to data theft, site defacement, or complete system compromise. WordPress users are urged to update their installations immediately and ensure all plugins and themes are from trusted sources. This incident underscores the critical importance of maintaining up-to-date software and monitoring for vulnerabilities in widely used platforms like WordPress, which powers a substantial portion of the internet.
Key Takeaways
- The vulnerability allows SQL injection attacks, which can lead to data theft, authentication bypass, or remote code execution.
- WordPress Core: WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter.
- This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. CVE-2026-60137 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.