On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase its impact to unauthenticated remote code execution and is identified as CVE-2026-63030.

To protect WordPress users while sites are being updated, we will not be providing additional technical details at this time.

The WordPress Security Team has initiated automatic updates for sites running vulnerable versions. However, we strongly recommend confirming as soon as possible that your site has successfully updated

Click here to continue reading this article.