HIGHVulnerability
Verified
Global
CISA KEV: WordPress Core — WordPress Core SQL Injection Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Analysis
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-21. Remediation due: 2026-08-04.