{"id":"CVE-2026-60137","title":"WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.","summary":"WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-89"],"published":"2026-07-17","updated":"2026-07-18","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-60137","references":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf","label":"contact@wpscan.com"},{"url":"https://wordpress.org/news/2026/07/wordpress-7-0-2-release/","label":"contact@wpscan.com"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.78305,"epssPercentile":0.99572,"ingestedAt":"2026-07-18T21:25:08.011Z","kev":true,"exploited":true,"kevDateAdded":"2026-07-21","kevDueDate":"2026-08-04","kevRansomware":false,"exploits":{"github":11,"githubRepos":["https://github.com/codeb0ssx/Ultimate-wp2shell","https://github.com/Colere-Sys/wp2shell-poc","https://github.com/ebrasha/abdal-cve-2026-60137"],"metasploit":["auxiliary/scanner/http/wordpress_wp2shell_sqli","exploit/multi/http/wp_batch_desync_rce"],"checkedAt":"2026-09-21T15:29:51.444Z"},"exploitAvailable":true,"slug":"CVE-2026-60137","body":"## Overview\n\nWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":73,"depthScoreParts":{"impact":32.5,"likelihood":15.7,"exploitation":25,"ransomware":0},"changes":[{"seq":5389,"id":"CVE-2026-60137","ts":1788887275759,"field":"exploit_available","old":"false","new":"true"},{"seq":4272,"id":"CVE-2026-60137","ts":1788886390415,"field":"exploit_available","old":"true","new":"false"},{"seq":3021,"id":"CVE-2026-60137","ts":1788883054020,"field":"exploit_available","old":"false","new":"true"},{"seq":2050,"id":"CVE-2026-60137","ts":1788882458232,"field":"exploit_available","old":"true","new":"false"},{"seq":1124,"id":"CVE-2026-60137","ts":1788881895270,"field":"exploit_available","old":"false","new":"true"},{"seq":182,"id":"CVE-2026-60137","ts":1787603671346,"field":"epss","old":"0.731","new":"0.79786"},{"seq":124,"id":"CVE-2026-60137","ts":1786218562038,"field":"epss","old":"0.79029","new":"0.731"},{"seq":96,"id":"CVE-2026-60137","ts":1784920498721,"field":"epss","old":"0.20395","new":"0.77974"},{"seq":77,"id":"CVE-2026-60137","ts":1784747475509,"field":"epss","old":"0.04026","new":"0.20395"},{"seq":72,"id":"CVE-2026-60137","ts":1784660984514,"field":"exploited","old":"false","new":"true"},{"seq":71,"id":"CVE-2026-60137","ts":1784660984514,"field":"kev","old":"false","new":"true"}]}