WordPress Core: CVE-2026-60137 is being actively exploited

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated

Original source: CISA KEV

LIVETHREAT WIRE
News
Partner Lens
?
Sign upSave your progress
Partner Lens active — NorthGate Security. Reviews & Academy vendor maps reflect their stack.remove