ThreatCluster

CISA Alerts on Actively Exploited SQL Injection Vulnerabilities in WordPress

First seen 22 Jul 2026, 18:55 UTC CybersecuritynewsGbhackers 95% similarity 73

Article Content

Browse articles
ThreatCluster

CISA has identified two critical SQL injection vulnerabilities in WordPress Core, CVE-2026-60137 and CVE-2026-63030, as actively exploited in the wild. Both vulnerabilities were published on July 17, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on July 21, 2026. These flaws allow attackers to compromise websites and potentially execute remote code. The vulnerabilities arise from inadequate validation of untrusted input in WordPress themes and plugins. The first public proof of concept (PoC) for CVE-2026-60137 was released on July 19, while CVE-2026-63030 had its PoC available a day earlier on July 18. Website administrators are urged to apply patches immediately to mitigate risks.

Key Points: • CISA has classified CVE-2026-60137 and CVE-2026-63030 as actively exploited vulnerabilities. • Both vulnerabilities allow for SQL injection attacks that could lead to remote code execution. • Website administrators are advised to apply patches urgently to protect against these threats.

ThreatCluster AI

Timeline

2026-07-17
CVE-2026-60137 published
A critical SQL injection vulnerability in WordPress Core was disclosed, affecting core functionality.
Gbhackers
2026-07-17
CVE-2026-63030 published
Another critical SQL injection vulnerability in WordPress Core was disclosed, similar to CVE-2026-60137.
Cybersecuritynews
2026-07-18
First public PoC for CVE-2026-63030
The first proof of concept for CVE-2026-63030 was made available, demonstrating the exploit.
Cybersecuritynews
2026-07-19
First public PoC for CVE-2026-60137
The first proof of concept for CVE-2026-60137 was released, showcasing the vulnerability.
Gbhackers
2026-07-21
CVE-2026-60137 and CVE-2026-63030 added to CISA KEV
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog due to active exploitation.
Gbhackers
2026-07-22
CISA issues warning
CISA warns that the vulnerabilities are actively exploited, urging immediate patching by affected users.
Gbhackers

Community

Browse all →