WordPress Core SQL Injection Vulnerability

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

Published 26 Aug 2026Updated 26 Aug 2026146 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.