Skip to content
ThreatCluster

CISA Alerts on Actively Exploited SQL Injection Vulnerabilities in WordPress

First seen 22 Jul 2026, 18:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 23, 2026 at 18:35 UTC
  • CISA has classified CVE-2026-60137 and CVE-2026-63030 as actively exploited vulnerabilities.
  • Both vulnerabilities allow for SQL injection attacks that could lead to remote code execution.
  • Website administrators are advised to apply patches urgently to protect against these threats.

CISA has identified two critical SQL injection vulnerabilities in WordPress Core, CVE-2026-60137 and CVE-2026-63030, as actively exploited in the wild. Both vulnerabilities were published on July 17, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on July 21, 2026. These flaws allow attackers to compromise websites and potentially execute remote code. The vulnerabilities arise from inadequate validation of untrusted input in WordPress themes and plugins. The first public proof of concept (PoC) for CVE-2026-60137 was released on July 19, while CVE-2026-63030 had its PoC available a day earlier on July 18. Website administrators are urged to apply patches immediately to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 61d ago How this analysis works

Timeline

2026-07-17
CVE-2026-60137 published
A critical SQL injection vulnerability in WordPress Core was disclosed, affecting core functionality.
Gbhackers
2026-07-17
CVE-2026-63030 published
Another critical SQL injection vulnerability in WordPress Core was disclosed, similar to CVE-2026-60137.
Cybersecuritynews
2026-07-18
First public PoC for CVE-2026-63030
The first proof of concept for CVE-2026-63030 was made available, demonstrating the exploit.
Cybersecuritynews
2026-07-19
First public PoC for CVE-2026-60137
The first proof of concept for CVE-2026-60137 was released, showcasing the vulnerability.
Gbhackers
2026-07-21
CVE-2026-60137 and CVE-2026-63030 added to CISA KEV
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog due to active exploitation.
Gbhackers
2026-07-22
CISA issues warning
CISA warns that the vulnerabilities are actively exploited, urging immediate patching by affected users.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track Cybersecurity and Infrastructure Security Agency and CVE-2026-60137 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed