WordPress Core Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
CVSS Score
9.8
CRITICAL
Published
21 Jul 2026 00:00
Modified
N/A
Vendor
WordPress
Product
Core
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-436
Affected Systems
WordPress
Core
WordPress
Core
External Links
KEV Status
Known Exploited Vulnerability