Skip to main content

Cybersecurity Weather

Global observatory

← Events

CVE-2026-60137

exploitation · critical · Evidence score 90

Vendor
WordPress
Affected software
WordPress Core
Exploitation signal
Listed in CISA Known Exploited Vulnerabilities
EPSS
0.731

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

Provenance

  • CISA Known Exploited Vulnerabilities

    21 July 2026, 10:00 AM AEST

CVE-2026-60137 | Cyber Weather Index