Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

[KEV] CVE-2026-60137 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-60137 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-60137 is a SQL injection vulnerability in WordPress Core that can be exposed when a WordPress plugin or theme passes untrusted input to a vulnerable parameter.

Technical Detail

The flaw allows attacker-controlled input to influence SQL queries under affected plugin or theme integration conditions. Successful exploitation may permit unauthorized database access or modification, depending on the query context and database privileges available to WordPress. The vulnerability can be chained with CVE-2026-63030 to enable unauthenticated remote code execution on default WordPress installations.

Exploitation Status

CISA has confirmed active exploitation in the wild. Exploit maturity is operational, indicating that working exploitation capability is available and has been used in real-world activity rather than existing only as a proof of concept.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize remediation of WordPress Core and CVE-2026-63030 together because the reported attack chain can result in unauthenticated remote code execution. Apply vendor-provided security updates as soon as available, and review installed plugins and themes for code paths that pass request-derived or otherwise untrusted input into WordPress database-query parameters. CISA added this vulnerability to the Known Exploited Vulnerabilities Catalog on July 21, 2026; under CISA Binding Operational Directive 22-01, federal civilian executive branch agencies must patch by August 11, 2026, or apply mitigations. Monitor WordPress and web-server logs for unexpected requests targeting plugin or theme endpoints, anomalous database-query errors, unauthorized administrative changes, newly created files, and suspicious PHP execution. Specific indicators of compromise and threat actor attribution have not been confirmed.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →