CVE-2026-60137
exploitation · critical · Evidence score 90
- Vendor
- WordPress
- Affected software
- WordPress Core
- Exploitation signal
- Listed in CISA Known Exploited Vulnerabilities
- EPSS
- 0.731
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Provenance
CISA Known Exploited Vulnerabilities
21 July 2026, 10:00 AM AEST