HIGHVulnerability
Verified
Global

CISA KEV: WordPress Core — WordPress Core Interpretation Conflict Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

Analysis

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-21. Remediation due: 2026-07-24.

Indicators of Compromise (2)

CVE (2)
CVE-2026-60137
CVE-2026-63030
Source Attribution

Originally published by CISA KEV on Jul 21, 2026. Verified by: CISA.

Related Threats