CVE-2026-60137 CRITICAL

WordPress Core Vulnerability
Generated: 10 Oct 2026 19:56 • CVE Threat Intelligence

Description

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

9.8
CVSS CRITICAL

Details

Published
21 Jul 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
WordPress
Product
Core
Fix Version
Vendor Patch / Mitigation Available

References