CVE-2026-60137
exploitedWordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
signal timeline
- CISA KEV · 29d ago
connections
first seen 28d ago · last seen 4m ago
intelyard daily
One short email each weekday: what mattered in tech, written from source data and checked by a human. No account needed, one-click unsubscribe, and we never sell or share the address.