WordPress Core
WordPress Core SQL Injection Vulnerability — WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to
Original Disclosure
https://nvd.nist.gov/vuln/detail/CVE-2026-60137
Severity
high
Sector
tech
Disclosure date
July 21, 2026
Indexed
1 day, 5 hours ago