CVE-2026-60137

Published Jul 17, 2026

Last updated a month ago

Exploit knownCVSS medium 5.9
WordPress
web application
Zero-day
Open source
SQL injection
wp2shell

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-60137 is a SQL injection vulnerability found in WordPress versions 6.8 and later. This flaw arises from the improper sanitization of the `author__not_in` parameter within `WP_Query` when untrusted data is passed to it by a plugin or theme. This vulnerability allows crafted input to alter a database query, potentially leading to unauthorized access or manipulation of data. Patches have been released for affected versions, specifically in WordPress 6.8.6, 6.9.5, and 7.0.2, as well as 7.1 beta2.

Description
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Source
contact@wpscan.com
NVD status
Analyzed
Products
wordpress

Insights

Analysis from the Intruder Security Team
Published Jul 17, 2026 Updated Jul 23, 2026

This SQL injection vulnerability is the second half of a critical exploit chain alongside CVE-2026-63030. On its own this vulnerability would require a plugin or theme to pass untrusted input — but when combined with CVE-2026-63030's authentication bypass, it becomes exploitable on stock WordPress with no plugins installed. This vulnerability can be used to gain code execution.

WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are affected. Update to WordPress 6.9.5 or 7.0.2 immediately. Both CVEs were patched in the same security release.

WordPress Core contains an SQL injection vulnerability in WP_Query where a query parameter is inserted directly into SQL without sanitisation when provided as a string value.

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.9
Impact score
3.6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
WordPress Core SQL Injection Vulnerability
Exploit added on
Jul 21, 2026
Exploit action due
Aug 4, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-89

Social media

Hype score
Not currently trending
  1. 【WAFログ速報】 162.19.94.70(2回): SQLインジェクション攻撃を検知。/wp-json/batch/v1等に対してSQL構文を含むリクエストを送信し、データベースの脆弱性を探る試行が確認された(CVE-2026-63030、CVE-2026-60137) #WAF #

    @zerizerizeri_bl

    30 Aug 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 【WAFログ速報】 85.105.178.126(2回): SQLインジェクション攻撃を検知。/wp-json/batch/v1等に対してSQL構文を含むリクエストを送信し、データベースの脆弱性を探る試行が確認された。(CVE-2026-63030、CVE-2026-60137) #W

    @zerizerizeri_bl

    30 Aug 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 August Linux Patch Wednesday: record 3,060 vulns (+52%); 3 exploited in the wild - Jenkins RCE CVE-2026-53435, WordPress CodeInj CVE-2026-60137, SPIP RCE CVE-2026-77647 + 127 with public exploits. #LinuxPatchWednesday #Linux #Vulristics ➡️ https://t.co/pGlcEtfrmg https:/

    @leonov_av

    28 Aug 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. WP2Shell: zero credentials, full WordPress takeover. CVE-2026-63030 + CVE-2026-60137 = CVSS 9.8, CISA KEV. Affects WP 6.9.x and 7.0.x. 43% of all websites. Patch: update to 6.9.5 or 7.0.2. https://t.co/Y4itNUQzh0 #WordPress #RCE

    @DecryptionDigst

    21 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #CVE-2023-46604 CVE-2026-61241 CVE-2025-6934 CVE-2025-24893 CVE-2026-60137 CVE-2026-63030 ..🧵👇

    @exploitgrid

    20 Aug 2026

    65 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Saxony’s data protection authority warns WordPress and Joomla operators about critical vulnerabilities. Key actions: 🩹 Patch CVE-2026-60137, CVE-2026-63030, and CVE-2026-48907 📣 Assess GDPR notification duties after unauthorized access Learn more: https://t.co/JpDcR5xp6

    @DataGuidance

    20 Aug 2026

    154 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. WordPress Coreの脆弱性 CVE-2026-63030 / CVE-2026-60137 (通称「wp2shell」)についてまとめてみた - piyolog https://t.co/644Z5usxe5

    @giw_news

    17 Aug 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 「うちはn8nも管理画面も無いから関係ない」- コーポレートサイトがWordPressなら、それは違います。 WordPress本体にログイン不要のコード実行の穴(CVE-2026-63030・CVE-2026-60137)。 CISAが既知悪用リストに追加済みで

    @n8nFlowMaster

    15 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core https://t.co/wGsjJZM6sJ https://t.co/cQzcPBhQQd

    @IT_Peurico

    10 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. ❗ Critical 'wp2shell' WordPress Vulnerabilities: Active Exploitation for Webshell Installation Two critical vulnerabilities in WordPress Core, collectively known as 'wp2shell' (CVE-2026-63030 and CVE-2026-60137), are b… https://t.co/4VzO64atAf #InfoSec #WordPress #RCE #SQLi

    @BytesNora

    9 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Critical: CVE-2026-60137; WordPress SQL Injection in WP_Query Exposes Databases and Completes the wp2shell RCE Chain (CVSS 9.1) Read the full breakdown here: https://t.co/tCUQOLpJhO #vulnerability #CVE #sqlinjection #cybersecurity #cyberdefense #threatdetectionresponse

    @SarahCross80725

    8 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core https://t.co/zwsXqdWSAj https://t.co/aWBA5WauZE

    @TechMash365

    5 Aug 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Outbreak Alert- There's been exploitation attempts targeting the WP2Shell attack chain (CVE-2026-63030 and CVE-2026-60137), a critical unauthenticated remote code execution (RCE) vulnerability affecting WordPress Core. Learn more: https://t.co/ZHpUsb0qq6 https://t.co/tFAFSdtO0r

    @KootekSecurity

    5 Aug 2026

    16 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. WordPress pod ostrzałem. Łańcuch WP2Shell — CVE-2026-63030 + CVE-2026-60137 — może umożliwić atakującemu bez logowania przejście od SQL Injection do zdalnego wykonania kodu. Problem dotyczy rdzenia WordPressa, a CISA potwierdziła aktywne wykorzystanie. #Cyberbezbiec

    @marekitlab

    4 Aug 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Every WordPress Site's Nightmare: Pre-Auth RCE via wp2shell A stock WordPress install can be taken over by one anonymous request. Inside wp2shell: CVE-2026-60137 + CVE-2026-63030. https://t.co/EITyihymsb

    @Djax_Alpha

    3 Aug 2026

    285 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 CVE-of-the-Day: CVE-2026-60137 — WordPress shipped a SQL injection in core. Not a plugin. Core. What it is: Any theme or plugin that passes user-controlled input into that query arg lets an attacker inject SQL straight into the database layer. No login needed on affected s

    @YourDailyCVE

    1 Aug 2026

    8 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  17. 🏅今週のはてなブログランキング〔2026年7月第4週〕より、おすすめエントリーを紹介します🏅 WordPress Coreの脆弱性 CVE-2026-63030 / CVE-2026-60137 (通称「wp2shell」)についてまとめてみた- piyolog https://t.co/s67gKRx08O piy

    @hatenablog

    30 Jul 2026

    672 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. PoC: [CVE-2026-63030/CVE-2026-60137] Pre Authentication RCE in WordPress Core 👾💥 - https://t.co/ZDVEsm6M9Q - https://t.co/JOUKcKrnbh - https://t.co/gI3T9ZxbAV - https://t.co/4AxAJTRmyi - https://t.co/6ngEvl8Uv6 - https://t.co/VUJrmtsHZN Join team 👉https://t.co/cADA5D

    @luckyhacker43

    29 Jul 2026

    385 Impressions

    1 Retweet

    13 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  19. wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core https://t.co/3NQibx85p9 https://t.co/eCzzoUEUrQ

    @dansantanna

    28 Jul 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. PoC: [CVE-2026-63030/CVE-2026-60137] Pre Authentication RCE in WordPress Core 👾💥 - https://t.co/ZDVEsm6M9Q - https://t.co/JOUKcKrnbh - https://t.co/gI3T9ZxbAV - https://t.co/4AxAJTRmyi - https://t.co/6ngEvl8Uv6 - https://t.co/VUJrmtsHZN Join team 👉https://t.co/cADA5D

    @luckyhacker43

    28 Jul 2026

    72 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core https://t.co/h8mb68eNHo https://t.co/UVlXYsZkCA

    @pcasano

    28 Jul 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 CERT-FR warns that CVE-2026-63030 is being exploited against WordPress. When chained with CVE-2026-60137, an unauthenticated attacker may achieve remote code execution on affected WordPress versions. Update to the latest supported release immediately. #WordPress #CVE

    @XQOPTRX

    27 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. WP2Shell: The WordPress Exploit Hitting Sites Right Now (CVE-2026-63030) https://t.co/EldDEeSG8w WP2Shell chains CVE-2026-63030 and CVE-2026-60137 to take over WordPress sites with no login. Check if your version is affected, patch to 7.0.2, and learn how… #WordpressSecurity

    @topsydehost

    27 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core https://t.co/REXG4Dofjn https://t.co/tiJEO6mItF

    @Art_Capella

    27 Jul 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. WordPress fixed SQLi (CVE-2026-60137) and unauth RCE (CVE-2026-63030). Cloudflare deployed WAF rules, but still said patch. Headers show browser policy; a WAF reduces exposure; neither proves app version. Posture is evidence, not attestation.

    @ThisIsSecURL

    27 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. WordPress shipped emergency fixes on July 17, 2026 for wp2shell — a pre-auth RCE in core, not a plugin or theme, affecting the engine itself. The update was forced onto affected sites. CVE-2026-63030 + CVE-2026-60137 https://t.co/G1ILKleDDW

    @chsxthwik

    27 Jul 2026

    100 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  27. wp2shell (CVE-2026-63030 + CVE-2026-60137) expliqué simplement : 2 bugs anodins dans le core WordPress → 1. confusion de route dans l'API REST batch 2. injection SQL via WP_Query Chaînés = RCE pré-auth sur 42% du web. https://t.co/NlezVQNVID https://t.co/V9ZhPUJa08

    @Fransosiche

    26 Jul 2026

    320 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 【WordPress使ってる人は今すぐ確認】 CVSS 9.8の緊急脆弱性「wp2shell」(CVE-2026-63030 / CVE-2026-60137)。 プラグイン無しの素のWPでも "認証なしで乗っ取り" が可能。 PoCは既に出回り、実際の攻撃も確認されています。

    @ORIHUSAY02

    26 Jul 2026

    650 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  29. I scanned 2,181 Quebec small-business WordPress sites 7 days after wp2shell dropped. 8.8% of the ones exposing their version were still on a build vulnerable to the RCE chain (CVE-2026-60137 + CVE-2026-63030). Data below 👇

    @ericstamantpro

    25 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  30. Everyone's been talking about WP2Shell (CVE-2026-63030 + CVE-2026-60137) over the past few days. Ended up finding an affected target while bug hunting, so naturally I had to test it. #bugbounty #bounty #HackerOne #hacking #cybersecurity #infosec #wp2shell #wordpress https://t.c

    @NvrjRy

    25 Jul 2026

    13 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  31. wp2shell: unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137). No plugin needed. Patched July 17 (6.9.5/7.0.2), both CVEs now in CISA KEV. Check your version today. 🇬🇧 https://t.co/HxtFWxXnls 🇩🇪 https://t.co/gZo7OtSDrA #CyberSecurity #WordPress

    @DIESEC_GmbH

    24 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. If you run WordPress, patch now. Two critical Core RCE flaws (CVE-2026-63030, CVE-2026-60137) are being exploited to plant webshells via the REST API — probing started within hours of disclosure. Update to 7.0.2 / 6.9.5 / 6.8.6. https://t.co/xBcgG9EYGj https://t.co/dm03JssmWI

    @genztechblog

    24 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Two critical WordPress Core flaws (CVE-2026-63030, CVE-2026-60137) are being actively exploited to run code through the REST API and plant hidden webshells. Attackers began probing within hours. Update to 7.0.2, 6.9.5 or 6.8.6 now. https://t.co/xBcgG9EYGj

    @genztechblog

    24 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. Две критические уязвимости WordPress: CVE-2026-60137 и CVE-2026-63030 https://t.co/aKjcrkBaMF #crimeakarro #karrolinux #itservicelinux

    @ASPbazi

    22 Jul 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. WordPress под ударом: опубликован PoC для цепочки RCE "wp2shell". Исследователи раскрыли детали атаки, объединяющей две уязвимости: • CVE-2026-63030 • CVE-2026-60137 Под угрозой

    @mnyadox

    22 Jul 2026

    5 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Warning: #Wordpress patched a critical CVE-2026-63030 which can be chained with CVE-2026-60137 to allow unauthenticated remote code execution. https://t.co/ot2c81HyF6 #RCE, #PoC available and #ActivelyExploited #patch #patch #patch

    @CCBalert

    22 Jul 2026

    290 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. https://t.co/5wJAJBBLX5 CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained

    @BentleyAudrey

    22 Jul 2026

    1132 Impressions

    3 Retweets

    16 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  38. Two vulnerabilities in WordPress Core (CVE-2026-63030 and CVE-2026-60137) can be chained for unauthenticated remote code execution. No plugins or special config required. Exploitation is already active. PoC code is public. Full breakdown: https://t.co/qUZI7zPKw8 https://t.co/Vf

    @orcasec

    22 Jul 2026

    153 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  39. WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell)https://t.co/qDEpoXp3nU ワードプレス恐ろしい!w クライアントからクレームこないように速やかに対応しましょう!

    @shinyalee

    22 Jul 2026

    18 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  40. WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://t.co/RhnvECkomj

    @ohhara_shiojiri

    22 Jul 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) https://t.co/mn9mTXWv3w

    @roaring_dog

    22 Jul 2026

    129 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://t.co/83aTz5Hc5q

    @fyi787

    22 Jul 2026

    95 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  43. WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) https://t.co/er9X9iy7xy

    @ICATalerts

    22 Jul 2026

    4863 Impressions

    18 Retweets

    25 Likes

    6 Bookmarks

    0 Replies

    1 Quote

  44. Baca disini: https://t.co/WRWJS1v9k6 Dua celah keamanan kritis WordPress (CVE-2026-60137 dan CVE-2026-63030) atau WP2Shell dieksploitasi peretas untuk mengambil alih situs tanpa perlu login ataupun menggunakan plugin tertentu. ~NJ #WordPress https://t.co/zNWDZ9hJVO

    @KompasTekno

    22 Jul 2026

    220 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. IPA 重要 | WordPressの脆弱性対策について(CVE-2026-60137、CVE-2026-63030:wp2shell) https://t.co/R5m0dEtbmu #itsec_jp

    @itsec_jp

    22 Jul 2026

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。DD-WRTのCVE-2021-27137、LangflowのCVE-2026-0770、WordPressのCVE-2026-63030とCVE-2026-60137。対処期限は前3件が3日

    @__kokumoto

    21 Jul 2026

    708 Impressions

    0 Retweets

    3 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  47. WordPress exposure is not closed by patching alone. CVE-2026-63030 and CVE-2026-60137 can turn an anonymous request into code execution, so patch, review REST/API logs, and hunt for persistence or backdoors left before remediation. https://t.co/R12CWCeoAW

    @TheClawdLab

    21 Jul 2026

    55 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. Three days. Millions of WordPress sites. Two CVEs chained for RCE via plugin upload. DarkReading confirms active exploitation of CVE-2026-60137 + CVE-2026-63030. The structural rot: WordPress has zero code-signing requirement for plugins. https://t.co/2YmYMq7BsA

    @QubbleOfficial

    21 Jul 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  49. 🚨 4 new CISA KEV adds today CVE-2021-27137, CVE-2026-0770, CVE-2026-63030, CVE-2026-60137 https://t.co/0StDFCzdCI #boarnet #cybersecurity #cisakev #cve #threatintelligence #malware

    @boarnetio

    21 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. It's Already When. — Field Note Three flaws are under active exploitation this week: WordPress wp2shell (CVE-2026-63030 + CVE-2026-60137), ServiceNow AI Platform CVE-2026-6... https://t.co/wxXexX4AWF #CyberSecurity #BlueTeam https://t.co/a37qOMNIND

    @itsalreadywhen

    21 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations