DIRAS TAKE
Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, and public exploit code exists — prioritize patching or mitigations immediately.
What is CVE-2026-60137?
An attacker can perform SQL injection against WordPress Core by supplying crafted input to the author__not_in WP_Query parameter when a plugin or theme passes untrusted data, potentially exposing or altering database contents; see CVE-2026-60137. The flaw affects WordPress 6.8.0 through before 6.8.6, 6.9.0 through before 6.9.5, and 7.0.0 through before 7.0.2. Exploitation requires that a plugin or theme forwards untrusted input to the vulnerable parameter; no user interaction or credentials are required in the CVSS vector. The weakness is classified as CWE-89 (SQL Injection).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Which versions of WordPress Core are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 6.x | 6.8.0 – before 6.8.6 | 6.8.6 |
| 6.x | 6.9.0 – before 6.9.5 | 6.9.5 |
| 7.x | 7.0.0 – before 7.0.2 | 7.0.2 |
Is CVE-2026-60137 being exploited?
CISA added CVE-2026-60137 to the Known Exploited Vulnerabilities catalog on 2026-07-21, and US federal agencies must remediate it by 2026-08-04. Public exploit code is also available.
How to fix CVE-2026-60137
- Upgrade WordPress to a fixed release: 6.8.6, 6.9.5, or 7.0.2 as appropriate for your branch.
- If immediate upgrade is not possible, follow vendor guidance for mitigations and restrict internet exposure of affected sites.
- Audit plugins and themes for any code that passes untrusted input to author__not_in and sanitize or remove such calls.
- Monitor logs and database access for unusual queries or signs of exploitation.
Frequently asked questions
Is CVE-2026-60137 being actively exploited?
CISA added CVE-2026-60137 to its Known Exploited Vulnerabilities catalog on 2026-07-21 and set a remediation deadline of 2026-08-04; public exploit code is also available.
Which WordPress versions are affected by CVE-2026-60137?
WordPress Core versions 6.8.0 through before 6.8.6, 6.9.0 through before 6.9.5, and 7.0.0 through before 7.0.2 are affected.
Is there a patch for CVE-2026-60137?
Yes; fixed releases are 6.8.6, 6.9.5, and 7.0.2 for the respective branches.
Does CVE-2026-60137 require authentication?
The vulnerability can be triggered when a plugin or theme supplies untrusted input to author__not_in; the CVSS vector indicates no privileges or user interaction are required.
References
- nvd.nist.gov/vuln/detail/CVE-2026-60137
- cve.org/CVERecord?id=CVE-2026-60137
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137
- github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
- wordpress.org/news/2026/07/wordpress-7-0-2-release
- All WordPress CVEs on CVE Radar
- CVEs published in September 2026