🔴 Critical  |  Source: CISA Known Exploited Vulnerabilities


A critical vulnerability in WordPress Core allows attackers to perform SQL Injection, potentially leading to full Remote Code Execution on affected sites. The flaw stems from an interpretation conflict and is actively being exploited in the wild, as confirmed by CISA’s Known Exploited Vulnerabilities catalogue. It can be chained with a second vulnerability (CVE-2026-60137) to amplify impact.

Security Architect’s Take: Patch WordPress Core immediately to the remediated version — the CISA-mandated deadline of 24 July 2026 applies to federal agencies but should be treated as urgent for all environments. Audit any cloud-hosted WordPress deployments (e.g. on AWS, Azure, or GCP via managed app services or self-hosted VMs) and ensure WAF rules are in place to block SQL injection attempts while patching is underway.

Original advisory: CVE-2026-63030: WordPress Core