Medium severity5.9CISA KEVNVD Advisory· Published Jul 17, 2026· Updated Jul 29, 2026
CVE-2026-60137
CVE-2026-60137
Description
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: >=6.8,<6.8.6
- (no CPE)range: <6.8.6, <6.9.5, <7.0.2
- osv-coords2 versions
>= 6.8.0, < 6.8.6+ 1 more
- (no CPE)range: >= 6.8.0, < 6.8.6
- (no CPE)range: >= 6.8.0, < 6.8.6
Patches
Vulnerability mechanics
References
3- github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjfnvdVendor Advisory
- wordpress.org/news/2026/07/wordpress-7-0-2-release/nvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
31- Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!Rapid7 Blog · Aug 28, 2026
- Metasploit Wrap Up: Lot of summer shells and fit http profilesRapid7 Blog · Aug 14, 2026
- WordPress 7.0.3 Released: 12 Vulnerabilities Found and FixedPatchstack Blog · Aug 6, 2026
- WP2Shell WordPress Exploit Technical Analysis and Real Attack DataWordfence Blog · Jul 29, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)Wordfence Blog · Jul 23, 2026
- Don’t swing at everythingCisco Talos Intelligence · Jul 23, 2026
- Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without AuthenticationThe Hacker News · Jul 22, 2026
- CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the WildCyber Security News · Jul 22, 2026
- Ninety minutes: watching attackers weaponize the WordPress core RCEPatchstack Blog · Jul 22, 2026
- Critical wp2shell WordPress flaws exploited to install webshellsBleepingComputer · Jul 21, 2026
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningThe Hacker News · Jul 21, 2026
- WordPress: 2 Actively-Exploited Flaws Added to CISA KEVVypr Intelligence · Jul 21, 2026
- Attackers pummel critical WordPress vuln to create all sorts of mischiefThe Register Security · Jul 20, 2026
- wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a DecadeWordfence Blog · Jul 20, 2026
- 'WP2Shell' Opens Millions of WordPress Sites to Remote TakeoverDark Reading · Jul 20, 2026
- Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation DetailsCyber Security News · Jul 20, 2026
- Researchers Build WordPress Exploit Using OpenAI's GPTInfosecurity Magazine · Jul 20, 2026
- wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress CoreTenable Blog · Jul 20, 2026
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThe Hacker News · Jul 20, 2026
- 20th July – Threat Intelligence ReportCheck Point Research · Jul 20, 2026
- WP2Shell WordPress Vulnerabilities Exploited in the WildSecurityWeek · Jul 20, 2026
- Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 StoriesCyber Security News · Jul 19, 2026
- WordPress Core "wp2shell" RCE flaws get public exploits, patch nowBleepingComputer · Jul 18, 2026
- Two new high severity WordPress vulnerabilities, patch immediately!Help Net Security · Jul 18, 2026
- New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch ReleasedCyber Security News · Jul 18, 2026
- PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability ChainWordfence Blog · Jul 17, 2026
- CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress CoreRapid7 Blog · Jul 17, 2026
- Cloudflare WAF protects WordPress applications from two high-severity vulnerabilitiesCloudflare Blog · Jul 17, 2026
- Unauthenticated SQL Injection in WordPress Core Fixed in 7.0.2Patchstack Blog · Jul 17, 2026
- WordPress 7.0.2 ReleaseWordPress Core Security · Jul 17, 2026
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA Alerts