#vulns.comcp

← CVE intelligence

CVE-2026-60137 — WordPress Core SQL Injection Vulnerability

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

Severity
critical
Product
WordPress Core
Published
2026-07-21
EPSS
0.783
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.