← 最新レポートに戻る | 📚 アーカイブ一覧

🔴 CRITICAL 特集

CVE-2026-60137
Core (WordPress)

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

📅 CISA KEV追加日: 2026年07月21日  ⏰ 対応期限: 2026-08-04

🏢 中小企業への影響

この脆弱性が自社システムで使用しているソフトウェアに該当しないか確認してください。

✅ 今すぐできる対策

🔗 一次情報源

CISA KEV / JPCERT/CC / JVN iPedia