๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-60137: WordPress Core SQL Injection Vulnerability
Summary
WordPress Core has a SQL injection vulnerability (a type of attack where malicious database commands are hidden in user input) that occurs when plugins or themes process untrusted data. This flaw can be combined with another vulnerability to let attackers without login credentials execute arbitrary code on standard WordPress sites.
Solution / Mitigation
Apply mitigations according to vendor instructions and follow CISA's BOD 26-04 guidance on prioritizing security updates. If mitigations are unavailable, discontinue use of the product. The patching deadline is 2026-08-04. See WordPress 7.0.2 release notes at https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ for specific update instructions.
Vulnerability Details
EPSS: 4.0%
Yes
๐ฅ Actively Exploited
July 20, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60137
First tracked: July 21, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%