TL;DR
A critical SQL injection vulnerability in WordPress Core, identified as CVE-2026-60137, is currently being exploited by attackers. This flaw allows unauthenticated remote code execution, especially when combined with CVE-2026-63030, putting affected websites at serious risk.
Cybersecurity officials have confirmed that the CVE-2026-60137 SQL injection vulnerability in WordPress Core is being actively exploited by malicious actors. This flaw allows attackers to execute arbitrary SQL commands, potentially compromising affected websites, especially when combined with CVE-2026-63030. The vulnerability’s exploitation underscores the urgent need for website administrators to apply patches and monitor for suspicious activity, especially in light of recent SharePoint deserialization vulnerabilities.
The CVE-2026-60137 vulnerability exists within WordPress Core when untrusted input is passed to database query parameters, enabling SQL injection. Security researchers have identified active exploitation campaigns targeting sites that have not yet applied security updates, similar to those seen with SonicWall SMA1000 appliances. The flaw can be chained with CVE-2026-63030, an additional vulnerability that allows unauthenticated remote code execution, increasing the severity of the threat. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, urging immediate mitigation measures. WordPress.org has released security patches addressing this flaw, but many sites remain unpatched, leaving them vulnerable to attack. Experts warn that attackers could leverage this vulnerability to access sensitive data, deface websites, or establish persistent backdoors.Implications for WordPress Site Security and Data Integrity
This vulnerability’s active exploitation presents a significant risk to the millions of websites running WordPress, which powers approximately 43% of the web. Unpatched sites are vulnerable to data breaches, defacement, and further exploitation, including the potential for attackers to take control of entire websites. The chaining with CVE-2026-63030 amplifies the threat, enabling attackers to execute malicious code without user authentication. This situation underscores the importance of timely patching and vigilant monitoring for signs of compromise, especially given the widespread use of WordPress in both small and enterprise environments.

WordPress Security: Essential WordPress Security Plugins and Step-by-Step Guide to Securing Your WordPress Website and Stopping Hackers (WordPress Security, WordPress Plugins, WordPress Book 1)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Details of the WordPress Core SQL Injection Flaw and Exploitation Timeline
The CVE-2026-60137 flaw was identified by security researchers earlier this year as a SQL injection vulnerability within WordPress Core. It occurs when plugins or themes pass untrusted input directly into database queries without proper sanitization. Although WordPress issued patches to fix the issue, reports indicate many sites have not yet updated. The vulnerability can be exploited remotely without authentication, and when combined with CVE-2026-63030, it allows attackers to execute arbitrary code on vulnerable sites. The exploitation campaigns were first observed in late March 2026 and have since increased in frequency, prompting a CISA alert and widespread industry concern.
“The active exploitation of CVE-2026-60137 highlights the urgent need for WordPress site administrators to update their installations immediately.”
— CISA spokesperson
As an affiliate, we earn on qualifying purchases.
Extent of Exploitation and Impact on Different WordPress Versions
While active exploitation has been confirmed, the full scope of affected sites and the specific payloads used remain unclear. It is also uncertain how widespread the exploitation is across different WordPress versions and configurations. Security experts continue to investigate whether certain plugins or themes are more targeted than others, and how quickly sites are being patched.
SQL injection protection WordPress
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Recommended Actions and Monitoring for WordPress Users
Site administrators are advised to immediately update to the latest WordPress version that patches CVE-2026-60137. They should also review server logs for signs of compromise, disable vulnerable plugins or themes, and implement enhanced security measures such as Web Application Firewalls (WAFs). Security agencies are expected to release further guidance as the situation develops, and ongoing monitoring of exploit activity is anticipated.

Tapo 2K Pan Tilt Security Camera for Baby Monitor, Dog Camera,C211(2-Pack)
- High Definition Video: 2K clarity for detailed viewing
- Pan and Tilt Functionality: 360° horizontal and 114° vertical coverage
- Flexible Storage Options: Supports microSD and cloud storage
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What is CVE-2026-60137?
CVE-2026-60137 is a SQL injection vulnerability in WordPress Core that allows attackers to execute arbitrary SQL commands when untrusted input is passed to database queries.
How is the vulnerability being exploited?
Threat actors are actively using this flaw to compromise websites, often chaining it with CVE-2026-63030 to enable unauthenticated remote code execution.
What should WordPress site owners do now?
They should update WordPress to the latest version, review logs for suspicious activity, and consider security enhancements like WAFs and plugin audits.
Are all WordPress sites at risk?
Sites that have not applied recent security patches and run vulnerable plugins or themes are at risk. The exploitation is ongoing and widespread.
Will there be more updates or patches?
WordPress security teams have released patches addressing this flaw; further updates depend on ongoing research and threat developments.
Source: kev