CISA Alerts on Actively Exploited SQL Injection Vulnerabilities in WordPress
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CISA has identified two critical SQL injection vulnerabilities in WordPress Core, CVE-2026-60137 and CVE-2026-63030, as actively exploited in the wild. Both vulnerabilities were published on July 17, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on July 21, 2026. These flaws allow attackers to compromise websites and potentially execute remote code. The vulnerabilities arise from inadequate validation of untrusted input in WordPress themes and plugins. The first public proof of concept (PoC) for CVE-2026-60137 was released on July 19, while CVE-2026-63030 had its PoC available a day earlier on July 18. Website administrators are urged to apply patches immediately to mitigate risks.
Key Points: • CISA has classified CVE-2026-60137 and CVE-2026-63030 as actively exploited vulnerabilities. • Both vulnerabilities allow for SQL injection attacks that could lead to remote code execution. • Website administrators are advised to apply patches urgently to protect against these threats.