<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — WordPress</title><description>Actively exploited vulnerabilities affecting WordPress products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/wordpress.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-60137 — WordPress Core SQL Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-60137</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-60137</guid><description>This SQL injection flaw in WordPress Core becomes critical because it can be chained with a second vulnerability (CVE-2026-63030) to give an unauthenticated attacker full remote code execution on default WordPress installations — no login required. Any internet-exposed WordPress site is potentially at risk. Successful exploitation could allow complete site takeover, data theft, or use of the server as a launchpad for further attacks. The broad deployment of WordPress makes this a high-priority issue for any organization running it.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>Core</category></item><item><title>CVE-2026-63030 — WordPress Core Interpretation Conflict Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-63030</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-63030</guid><description>This WordPress Core flaw involves an interpretation conflict that enables SQL Injection, which can then be escalated to full Remote Code Execution on the server. When chained with CVE-2026-60137, the attack surface widens significantly. For organizations running WordPress — including self-hosted sites and managed instances — a successful exploit could allow an attacker to extract data, manipulate the database, and ultimately take complete control of the underlying server.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>Core</category></item></channel></rss>