Back to overview

CVE-2026-60137

CRITICAL KEV CISA Exploitation: ACTIVE
9.1
CVSS 3.1
Description
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Metadata

CVE ID
CVE-2026-60137
State
PUBLISHED
Assigner
WPScan
Reserved
2026-07-17 17:17 UTC
Published
2026-07-17 19:14 UTC
Last updated
2026-07-22 03:55 UTC
Primary CWE
CWE-89
CWE-89 Improper Neutralization of Special Elements used in a…
Vendor / Product
WordPress / WordPress
Sources
cve.org  ·  NVD

Severity & Metrics

9.1 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
no
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
WordPress Core SQL Injection Vulnerability
Vendor
WordPress
Product
Core
Added to KEV
2026-07-21
Due date
2026-08-04
Ransomware
Not known
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA description
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Affected products (1)
VendorProductPlatformVersions
WordPress WordPress 6.8.0 < 6.8.6, 6.9.0 < 6.9.5, 7.0.0 < 7.0.2
Weakness (CWE)
CWESourceDescription
cna CWE-89 SQL Injection
CWE-89 adp CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.1 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
5.9 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Back to overview