Skip to main content

WordPress security briefs

2 published alerts for WordPress products and services.

Actively exploited (KEV)

CVE-2026-63030

WordPress Core Interpretation Conflict Vulnerability

WordPress Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-63030). WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. CISA remediation due date: 2026-07-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-60137

WordPress Core SQL Injection Vulnerability

WordPress Core is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-60137). WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. CISA remediation due date: 2026-08-04. If you need help checking exposure, call (864) 335-9223.