vulnhighUnderground · Vulnerability
KEV agrega CVE-2026-60137 — WordPress / Core
OccurredJul 21, 2026 · 00:00 UTC
DetectedJul 21, 2026 · 15:43 UTC
SourceUnderground · Vulnerability
External ref.CVE-2026-60137
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
- cve_id
- CVE-2026-60137
- vendor_product
- WordPress / Core
No related events in the past 48h.