Vulnerability intelligence
CVE-2026-60137
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
78%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-21
Remediation
unknown
Federal deadline 2026-08-04
9 articles across 6 outlets · first covered Jul 18, 2026 · latest Jul 22, 2026
Coverage timeline
-
CISA adds DDWRT, Langflow and WordPress bugs to KEV listsecurityaffairs.com · Jul 22, 2026
-
CISA warns of active exploits in WordPress, Langflow, DDWRTsecurityonline.info · Jul 21, 2026
-
CISA flags critical WordPress SQLi flaw in KEV, urges patchcisa.gov · Jul 21, 2026
-
Critical WordPress Bug Lets Attackers Run Code Remotelysecurityonline.info · Jul 21, 2026
-
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeoverwww.darkreading.com · Jul 20, 2026
-
AI crafted WordPress exploit chain triggers urgent CVE patcheswww.infosecurity-magazine.com · Jul 20, 2026
-
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCEwww.securityweek.com · Jul 20, 2026
-
Public PoC exploits hit critical WordPress CVEs, urging patchessecurityaffairs.com · Jul 19, 2026
-
WordPress SQLi bug allows remote code execution, update nowsecurityonline.info · Jul 18, 2026