CISA Adds WordPress SQL Injection to KEV List
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
2 results for “cve-2026-60137”
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
A pair of newly identified vulnerabilities dubbed WP2Shell are being actively exploited in the wild, triggering forced site updates.