Skip to content
COOEY

EXPOSURES › CVE-2026-60137

CVE-2026-60137

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-60137 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

WordPress 6.6.11 exposed to RCE via unhandled input

Authenticated attackers with contributor access could inject scripts, leading to remote code execution in WordPress 6.6.11 and earlier versions.

Shame score — Authenticated attackers exploited a stored cross-site scripting vulnerability to inject scripts, enabling remote code execution in WordPress 6.6.11 and earlier versions.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.