• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-60137: sql injection in WordPress Core

An attacker can perform SQL injection against WordPress Core by supplying crafted input to the author__not_in WP_Query parameter when a plugin or theme passes untrusted data, potentially exposing or altering database contents; see CVE-2026-60137. The flaw affects WordPress 6.8.0 through before 6.8.6, 6.9.0 through before 6.9.5, and 7.0.0 through before 7.0.2. Exploitation requires that a plugin or theme forwards untrusted input to the vulnerable parameter; no user interaction or credentials are required in the CVSS vector.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
5.9MEDIUM
EPSS
0.05906
CWE
CWE-89
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, and public exploit code exists — prioritize patching or mitigations immediately.

What is CVE-2026-60137?

An attacker can perform SQL injection against WordPress Core by supplying crafted input to the author__not_in WP_Query parameter when a plugin or theme passes untrusted data, potentially exposing or altering database contents; see CVE-2026-60137. The flaw affects WordPress 6.8.0 through before 6.8.6, 6.9.0 through before 6.9.5, and 7.0.0 through before 7.0.2. Exploitation requires that a plugin or theme forwards untrusted input to the vulnerable parameter; no user interaction or credentials are required in the CVSS vector. The weakness is classified as CWE-89 (SQL Injection).

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Which versions of WordPress Core are affected?

BRANCHAFFECTEDFIXED
6.x6.8.0 – before 6.8.66.8.6
6.x6.9.0 – before 6.9.56.9.5
7.x7.0.0 – before 7.0.27.0.2

Is CVE-2026-60137 being exploited?

CISA added CVE-2026-60137 to the Known Exploited Vulnerabilities catalog on 2026-07-21, and US federal agencies must remediate it by 2026-08-04. Public exploit code is also available.

How to fix CVE-2026-60137

  1. Upgrade WordPress to a fixed release: 6.8.6, 6.9.5, or 7.0.2 as appropriate for your branch.
  2. If immediate upgrade is not possible, follow vendor guidance for mitigations and restrict internet exposure of affected sites.
  3. Audit plugins and themes for any code that passes untrusted input to author__not_in and sanitize or remove such calls.
  4. Monitor logs and database access for unusual queries or signs of exploitation.

Frequently asked questions

Is CVE-2026-60137 being actively exploited?

CISA added CVE-2026-60137 to its Known Exploited Vulnerabilities catalog on 2026-07-21 and set a remediation deadline of 2026-08-04; public exploit code is also available.

Which WordPress versions are affected by CVE-2026-60137?

WordPress Core versions 6.8.0 through before 6.8.6, 6.9.0 through before 6.9.5, and 7.0.0 through before 7.0.2 are affected.

Is there a patch for CVE-2026-60137?

Yes; fixed releases are 6.8.6, 6.9.5, and 7.0.2 for the respective branches.

Does CVE-2026-60137 require authentication?

The vulnerability can be triggered when a plugin or theme supplies untrusted input to author__not_in; the CVSS vector indicates no privileges or user interaction are required.

References