What is CVE-2026-60137?
CVE-2026-60137 is a vulnerability classified as Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), affecting WordPress (affected versions: 6.8.0 – < 6.8.6, 6.9.0 – < 6.9.5, and other affected versions). This vulnerability is rated Critical, with a CVSS score of 9.1. This vulnerability has been observed being exploited in the wild.