WordPress: CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks

WordPress: CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks

CISA Warns of Actively Exploited WordPress Core SQL Injection Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-60137, a critical SQL injection vulnerability in WordPress Core, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in real-world attacks. The flaw stems from improper input validation in database queries, allowing attackers to manipulate SQL statements particularly when themes or plugins fail to sanitize untrusted data.

The vulnerability poses a severe risk, especially for internet-facing WordPress instances, as it can be chained with CVE-2026-63030 an interpretation conflict flaw in WordPress Core to achieve unauthenticated remote code execution (RCE) on default installations. This combination enables attackers to escalate attacks beyond data theft, potentially compromising entire systems.

CISA designated both vulnerabilities as high-priority threats, adding them to the KEV catalog on July 21, 2026. Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies must apply patches or mitigations by August 4, 2026. The agency urges all organizations to assess exposure, prioritize internet-facing systems, and follow vendor guidance including temporary mitigations or service suspensions if patches are unavailable.

WordPress’s widespread use across enterprises, government, and small businesses makes these flaws particularly concerning. Threat actors frequently target the platform due to its plugin ecosystem and common misconfigurations, which expand attack surfaces. Automated scanning tools are already being used to identify vulnerable installations, with attackers leveraging SQL injection to extract data or prepare for further exploitation.

Security researchers emphasize the need for immediate updates to patched WordPress versions, audits of plugins/themes for secure coding practices, and the deployment of web application firewalls (WAFs) to block malicious input. Database query logging and behavioral monitoring can also aid in detecting exploitation attempts. The inclusion of CVE-2026-60137 in CISA’s KEV catalog underscores its urgency, as confirmed attacks highlight the growing threat to web infrastructure.

Source: https://gbhackers.com/cisa-warns-wordpress-core-sql-injection-vulnerability/

WordPress TPRM report: https://www.rankiteo.com/company/wordpress

"id": "wor1784723234",
"linkid": "wordpress",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology, Web Development',
                        'location': 'Global',
                        'name': 'WordPress',
                        'size': 'Widespread use across enterprises, '
                                'government, and small businesses',
                        'type': 'Content Management System (CMS)'}],
 'attack_vector': 'Internet-facing WordPress instances, plugin/theme '
                  'vulnerabilities',
 'data_breach': {'data_exfiltration': 'Potential data extraction'},
 'date_publicly_disclosed': '2026-07-21',
 'description': 'The U.S. Cybersecurity and Infrastructure Security Agency '
                '(CISA) has added CVE-2026-60137, a critical SQL injection '
                'vulnerability in WordPress Core, to its Known Exploited '
                'Vulnerabilities (KEV) catalog after confirming active '
                'exploitation in real-world attacks. The flaw stems from '
                'improper input validation in database queries, allowing '
                'attackers to manipulate SQL statements, particularly when '
                'themes or plugins fail to sanitize untrusted data. The '
                'vulnerability can be chained with CVE-2026-63030 to achieve '
                'unauthenticated remote code execution (RCE) on default '
                'installations.',
 'impact': {'data_compromised': 'Potential data theft',
            'operational_impact': 'Potential system compromise, remote code '
                                  'execution',
            'systems_affected': 'WordPress Core installations'},
 'lessons_learned': 'Threat actors frequently target WordPress due to its '
                    'plugin ecosystem and common misconfigurations, expanding '
                    'attack surfaces. Immediate patching and proactive '
                    'security measures are critical.',
 'post_incident_analysis': {'corrective_actions': 'Patching, secure coding '
                                                  'audits, WAF deployment, '
                                                  'monitoring',
                            'root_causes': 'Improper input validation in '
                                           'database queries, plugin/theme '
                                           'vulnerabilities'},
 'recommendations': ['Apply patches or mitigations by August 4, 2026 (FCEB '
                     'agencies)',
                     'Prioritize internet-facing systems',
                     'Audit plugins/themes for secure coding practices',
                     'Deploy web application firewalls (WAFs) to block '
                     'malicious input',
                     'Implement database query logging and behavioral '
                     'monitoring'],
 'references': [{'source': 'CISA Known Exploited Vulnerabilities (KEV) '
                           'catalog'}],
 'regulatory_compliance': {'regulatory_notifications': 'Binding Operational '
                                                       'Directive (BOD) 26-04 '
                                                       'for Federal Civilian '
                                                       'Executive Branch '
                                                       '(FCEB) agencies'},
 'response': {'adaptive_behavioral_waf': 'Deployment of web application '
                                         'firewalls (WAFs) to block malicious '
                                         'input',
              'containment_measures': 'Apply patches, temporary mitigations, '
                                      'or service suspensions if patches are '
                                      'unavailable',
              'enhanced_monitoring': 'Database query logging and behavioral '
                                     'monitoring',
              'remediation_measures': 'Immediate updates to patched WordPress '
                                      'versions, audits of plugins/themes for '
                                      'secure coding practices'},
 'stakeholder_advisories': 'CISA urges all organizations to assess exposure '
                           'and follow vendor guidance.',
 'title': 'CISA Warns of Actively Exploited WordPress Core SQL Injection Flaw',
 'type': 'SQL Injection, Remote Code Execution (RCE)',
 'vulnerability_exploited': ['CVE-2026-60137', 'CVE-2026-63030']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.