ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-60137

CRITICAL Export PDF

WordPress Core Vulnerability

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

CVSS Score
9.8
CRITICAL
Published
21 Jul 2026 00:00
Modified
N/A
Vendor
WordPress
Product
Core
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-89

Affected Systems

WordPress
Core
WordPress
Core

KEV Status

Known Exploited Vulnerability