TL;DR
A known SQL injection flaw in WordPress core, CVE-2026-60137, is currently being exploited by attackers. This vulnerability can enable unauthorized data access and site compromise. Experts warn immediate action is needed.
Cybersecurity officials have confirmed that the critical SQL injection vulnerability in WordPress core, identified as CVE-2026-60137, is actively being exploited by malicious actors, putting millions of websites at risk. This vulnerability allows attackers to execute arbitrary SQL commands, potentially gaining unauthorized access to sensitive data or compromising site integrity.
According to the Cybersecurity and Infrastructure Security Agency (CISA), CVE-2026-60137 affects WordPress core when plugins or themes pass untrusted input to database queries, leading to SQL injection. The flaw can be exploited without authentication, making it particularly dangerous. Security researchers have observed active exploitation campaigns since late February 2026, with attackers chaining this vulnerability with CVE-2026-58644 to escalate their privileges further. WordPress developers have acknowledged the issue and are working on a patch, but no official fix has been released yet. Site administrators are urged to review their configurations and apply security measures immediately to mitigate the risk.Implications of Active Exploitation for WordPress Users
This vulnerability’s active exploitation poses a serious threat to the security of WordPress websites, which power over 40% of the internet. Attackers can leverage CVE-2026-60137 to access sensitive user data, inject malicious code, or take control of affected sites. The exploitation’s unpatched status increases the urgency for site owners to implement protective measures, as successful breaches could lead to data theft, defacement, or further malware distribution.
WordPress Security: Essential WordPress Security Plugins and Step-by-Step Guide to Securing Your WordPress Website and Stopping Hackers (WordPress Security, WordPress Plugins, WordPress Book 1)

As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Details on the Vulnerability and Exploitation Campaigns
CVE-2026-60137 was identified as a SQL injection flaw within WordPress core, specifically when plugins or themes pass untrusted input to database queries. The vulnerability has been known since late February 2026, but recent reports confirm active exploitation. The attackers appear to be chaining this flaw with CVE-2026-63030, another vulnerability that allows privilege escalation, to maximize their control over compromised sites. Experts from cybersecurity firms and the WordPress security team have issued advisories, emphasizing the importance of immediate patching and monitoring.
“The active exploitation of CVE-2026-60137 underscores the urgent need for WordPress users to apply security updates and review their configurations.”
— CISA spokesperson
Unclear Aspects of the Exploitation and Patch Timeline
It is not yet clear how widespread the active exploitation is, or whether specific plugins or themes are more targeted. Details about the full scope of compromised sites remain undisclosed. Additionally, the timeline for an official security patch from WordPress has not been confirmed, leaving site owners vulnerable in the interim.
Expected Security Updates and Mitigation Steps
WordPress developers are expected to release a security patch addressing CVE-2026-60137 within the coming days. Meanwhile, site administrators should review their plugin and theme security, disable untrusted inputs where possible, and monitor network traffic for signs of intrusion. Cybersecurity agencies will likely issue further advisories as the situation develops.
Key Questions
What is CVE-2026-60137?
CVE-2026-60137 is a critical SQL injection vulnerability in WordPress core that allows attackers to execute arbitrary SQL commands, potentially compromising websites.
How are attackers exploiting this vulnerability?
Attackers are actively exploiting the flaw by passing malicious input through plugins or themes that do not properly sanitize data, chaining it with other vulnerabilities to escalate privileges or access sensitive data.
What should WordPress site owners do now?
Site owners should monitor official security advisories, avoid using untrusted plugins or themes, review their configurations, and apply updates as soon as they are available.
Is there a fix available yet?
As of now, no official patch has been released. WordPress developers are working on a fix, and site owners should stay alert for updates.
How serious is this threat?
This is a high-severity, actively exploited vulnerability affecting millions of websites, with significant risks including data breaches and site compromise.
Source: kev