CISA Alerts on Actively Exploited SQL Injection Vulnerabilities in WordPress
Article Content
- •CISA has classified CVE-2026-60137 and CVE-2026-63030 as actively exploited vulnerabilities.
- •Both vulnerabilities allow for SQL injection attacks that could lead to remote code execution.
- •Website administrators are advised to apply patches urgently to protect against these threats.
CISA has identified two critical SQL injection vulnerabilities in WordPress Core, CVE-2026-60137 and CVE-2026-63030, as actively exploited in the wild. Both vulnerabilities were published on July 17, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on July 21, 2026. These flaws allow attackers to compromise websites and potentially execute remote code. The vulnerabilities arise from inadequate validation of untrusted input in WordPress themes and plugins. The first public proof of concept (PoC) for CVE-2026-60137 was released on July 19, while CVE-2026-63030 had its PoC available a day earlier on July 18. Website administrators are urged to apply patches immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cybersecurity and Infrastructure Security Agency and CVE-2026-60137 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Chinese Hackers Exploit Zyxel Switch Vulnerability CVE-2026-7273 A Chinese-speaking threat actor has exploited a stack-based buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 switches, compromising 996 devices across 48 countries since August 17, 2026. The vulnerability allows unauthenticated attackers to execute OS commands via crafted HTTP requests. Zyxel released…