Wordpress Alert: Core facilitated SQL injection (CVE-2026-60137)

An affected WordPress version remains unpatched after the July 2026 security release. The documented flaw can let an attacker influence a database query under the advisory's conditions.

What it looks like

An affected WordPress version remains unpatched after the July 2026 security release.

Why it matters

The documented flaw can let an attacker influence a database query under the advisory's conditions.

What to check

Check the installed core version against the release's affected-version and backport notes.

Documentation

This is a documented WordPress core vulnerability. The linked release gives the affected versions and fixes. See WordPress 7.0.2 security release.