CISA Alerts on Actively Exploited SQL Injection Vulnerabilities in WordPress
ID: 1f1ca2e9-ca7a-5e9b-bda6-0cd59391aaf9
STIX ID: report--1f1ca2e9-ca7a-5e9b-bda6-0cd59391aaf9
Feed Name: ThreatCluster
Threat Score
CISA has identified two critical WordPress Core SQL injection vulnerabilities (CVE-2026-60137 and CVE-2026-63030) that are being actively exploited and can lead to remote code execution; public PoCs were released in mid‑July 2026 and both CVEs were added to CISA's Known Exploited Vulnerabilities catalog — administrators are urged to apply patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
