CISA has added CVE‑2026-60137 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects the WordPress Core product and is described as a SQL injection vulnerability that can be chained with CVE‑2026-63030 to permit an unauthenticated attacker to achieve remote code execution on default WordPress installations.
The vulnerability resides in the way WordPress Core handles untrusted input supplied by a plugin or theme to a specific parameter, allowing SQL injection. It has been assigned a CVSS v3 score of 9.1, which rates the issue as Critical. Successful exploitation could lead to unauthorized database access, and when combined with the referenced CVE, to arbitrary code execution on the host server. No patch or advisory is currently listed in the NVD entry.
Active exploitation has been confirmed, which is the basis for the KEV listing; there is no known use of this vulnerability in ransomware campaigns at this time. CISA has established a remediation deadline of 4 August 2026 for Federal Civilian Executive Branch (FCEB) agencies to address the flaw.
CISA directs agencies to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines. Although the directive binds FCEB agencies, all organisations should review their WordPress deployments for potential exposure.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-60137 and the CISA KEV catalogue.