Skip to content
CISA Known Exploited Vulnerability

CVE-2026-60137

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated

⚠ Actively exploited (CISA KEV) WordPress 2026
CISA catalog entry
Product
Core
Vendor
WordPress
Added to KEV
2026-07-21
Remediation due
2026-08-04