All CVEs
Vulnerability intelligence

CVE-2026-60137

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

CVSS Score
9.1
Critical
EPSS — Exploit Probability
78%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-21
Remediation
unknown
Federal deadline 2026-08-04
NVD entry PoC / advisory CISA KEV

9 articles across 6 outlets · first covered Jul 18, 2026 · latest Jul 22, 2026

Coverage timeline