logo

CISA Alerts on Actively Exploited SQL Injection Vulnerabilities in WordPress

ID: 1f1ca2e9-ca7a-5e9b-bda6-0cd59391aaf9

STIX ID: report--1f1ca2e9-ca7a-5e9b-bda6-0cd59391aaf9

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

...
...

CISA has identified two critical WordPress Core SQL injection vulnerabilities (CVE-2026-60137 and CVE-2026-63030) that are being actively exploited and can lead to remote code execution; public PoCs were released in mid‑July 2026 and both CVEs were added to CISA's Known Exploited Vulnerabilities catalog — administrators are urged to apply patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.