EXPOSURES › CVE-2026-60137
CVE-2026-60137
HIGH ⌖ ON CISA KEV · EXPLOITEDWordPress 6.6.11 exposed to RCE via unhandled input
Authenticated attackers with contributor access could inject scripts, leading to remote code execution in WordPress 6.6.11 and earlier versions.
Shame score — Authenticated attackers exploited a stored cross-site scripting vulnerability to inject scripts, enabling remote code execution in WordPress 6.6.11 and earlier versions.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.