Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

[KEV] CVE-2026-60137 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-60137 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-60137 is a SQL injection vulnerability in WordPress Core that is triggered when a plugin or theme passes untrusted input to an affected parameter, exposing the attack surface of any default WordPress installation running vulnerable third-party extensions.

Technical Detail

The flaw exists in WordPress Core's handling of unsanitized input passed through plugin or theme code to a vulnerable query parameter, allowing an attacker to inject arbitrary SQL. When chained with CVE-2026-63030, an unauthenticated attacker can escalate from SQL injection to full remote code execution on a default WordPress installation without requiring any prior authentication or user interaction. The combined exploit chain represents a critical risk despite the currently assigned CVSS score of 0.0, which should be treated as incomplete or pending revision given the confirmed exploitation activity.

Exploitation Status

CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities catalog on July 21, 2026. The exploit maturity is rated Operational, meaning a functional exploit capable of reliable use against real targets exists and is being actively used. The chained nature of this vulnerability with CVE-2026-63030 suggests the exploit is purpose-built and not a simple proof-of-concept.

Who Is Targeting This

No confirmed threat actor attribution has been established at this time. Reported attribution references no public attribution with medium confidence, meaning research or telemetry has suggested activity but no specific named actor or group has been publicly identified. No origin country or motivation has been attributed to the observed exploitation.

What To Do

Per CISA's Known Exploited Vulnerabilities catalog, organizations subject to BOD 22-01 must apply patches or mitigations by the required remediation date associated with the July 21, 2026 listing. Administrators should update WordPress Core to the latest patched release immediately and audit all installed plugins and themes to identify any that pass user-controlled input to database query parameters. As an interim measure, consider deploying a web application firewall with rules targeting SQL injection patterns against WordPress endpoints. Organizations should also monitor database query logs and web server access logs for anomalous SQL syntax or unexpected file write activity, which may indicate exploitation of the RCE chain. Given the unauthenticated attack vector and confirmed in-the-wild exploitation, this should be treated as a priority patch regardless of the anomalous CVSS score.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →