CVE-2026-60137 — WordPress Actively Exploited CVE
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated
A canonical-name-with-aliases system consolidates the post-Mandiant/TAG merger. WebPulse reads this as infrastructure for machine-speed triage.
When a single AI model writes production code and evaluates security posture in the same session, the framework underneath shapes the terrain it encounters.
CVE-2026-63030 and CVE-2026-60137 are being exploited to install persistent webshells through WordPress Core's plugin installer.
Two chained CVEs enable pre-authenticated code execution on standard WordPress installs. Patches shipped July 17 — sites that haven't applied them are exposed.