CVE-2026-60137: WordPress Core SQL Injection Vulnerability
Summary
A SQL injection vulnerability has been identified in WordPress Core, which can be exploited in conjunction with another CVE to achieve remote code execution on default installations. The vulnerability arises when plugins or themes process untrusted input.
IFF Assessment
This vulnerability allows unauthenticated attackers to gain remote code execution, posing a significant threat to WordPress websites and their data.
Severity
The vulnerability has a high impact on Confidentiality, Integrity, and Availability, and an attacker can exploit it remotely without authentication, leading to code execution.
CISA KEV: Listed as actively exploited. Federal patch due: August 04, 2026. Known ransomware use: Unknown.
Defender Context
Defenders must prioritize patching this critical SQL injection vulnerability in WordPress Core, especially given its potential to lead to remote code execution. The chaining with another CVE highlights the importance of keeping all components, including plugins and themes, updated and secure to prevent complex attack chains.