CVE-2026-60137
published 2026-07-17CVE-2026-60137: WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow…
PriorityP181medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-04
Exploited in the wild
EPSS
77.97%
99.5th percentile
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wordpress | wordpress | < 7.0.2 | 7.0.2 |
| wordpress | wordpress | >= 6.8 < 6.8.6 | 6.8.6 |
| wordpress | wordpress | >= 6.9 < 6.9.5 | 6.9.5 |
| wordpress | wordpress | >= 6.9.0 < 6.9.5 | 6.9.5 |
| wordpress | wordpress | >= 7.0 < 7.0.2 | 7.0.2 |
| wordpress | wordpress | >= 7.0.0 < 7.0.2 | 7.0.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck9.1CRITICAL
cisa5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
WordPress Core SQL Injection Vulnerability
cisa·2026-07-21·CVSS 5.9
CVE-2026-60137 [MEDIUM] CWE-89 WordPress Core SQL Injection Vulnerability
Vulnerability: WordPress Core SQL Injection Vulnerability
Affected: WordPress Core
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet
CISA
WordPress Core Interpretation Conflict Vulnerability
cisa·2026-07-21·CVSS 5.9
CVE-2026-63030 [MEDIUM] CWE-436 WordPress Core Interpretation Conflict Vulnerability
Vulnerability: WordPress Core Interpretation Conflict Vulnerability
Affected: WordPress Core
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching gu
WordPress
WordPress 7.0.2 Release
vendor_wordpress·2026-07-17·CVSS 9.1
CVE-2026-63030 [CRITICAL] WordPress 7.0.2 Release
Title: WordPress 7.0.2 Release
WordPress 7.0.2 is now available.
The 7.0.2 security release addresses one critical and one high severity security issue.
Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions.
To manually update you can visit your WordPress Dashboard, click “Updates”, and then click “Update Now”, or you can download WordPress 7.0.2 from WordPress.org . On sites that support automatic background updates, the update process will begin automatically.
Security updates included in this release
The security team would like to thank the following people for responsibly reporting vulnerabilities and allow
VulDB
WordPress up to 6.8.5/6.9.4/7.0.1 WP_Query sql injection (EUVD-2026-45279)
vuldb·2026-07-17·CVSS 9.1
CVE-2026-60137 [CRITICAL] WordPress up to 6.8.5/6.9.4/7.0.1 WP_Query sql injection (EUVD-2026-45279)
A vulnerability identified as critical has been detected in WordPress up to 6.8.5/6.9.4/7.0.1. This impacts an unknown function of the component WP_Query. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2026-60137. The attack is possible to be carried out remotely. No exploit exists.
VulnCheck
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
vulncheck·2026·CVSS 5.9
CVE-2026-60137 [MEDIUM] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Affected: WordPress WordPress
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://patchstack.com/database/wordpress/plugin/wordpress/vulnerability/wordpress-core-7-0-2-unauthenticated-sql-injection-vulnerability
Exploit PoC: https://vulncheck.com/xdb/226a2304a8c3; https://vulncheck.com/xdb/0cb204211eff; https://vulncheck.com/xdb/4b2d
VulnCheck
Interpretation Conflict
vulncheck·2026·CVSS 9.1
CVE-2026-63030 [CRITICAL] Interpretation Conflict
Interpretation Conflict
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://patchstack.com/database/wordpress/plugin/wordpress/vulnerability/wordpress-core-7-0-1-unauthenticated-remote-code-execution-vulnerability
No detection rules found.
Nuclei
WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
nuclei·CVSS 5.9
CVE-2026-63030 [MEDIUM] WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
WordPress core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are vulnerable to a pre-authentication timing-based blind SQL injection via the REST API batch endpoint. A route confusion vulnerability (CVE-2026-63030) allows nested batch requests to bypass authentication checks, while a SQL injection flaw (CVE-2026-60137) in the author_exclude parameter of /wp/v2/categories allows arbitrary SQL queries via a SLEEP-based timing oracle. An unauthenticated attacker can extract the full database contents including user credentials.
Template:
id: CVE-2026-63030
info:
name: WordPress Core 6.9-7.0.1 - Pre-Auth Blind SQL Injection (Batch-Route Confusion)
author: slcyber,mielverkerken,pdteam
severity: critical
d
Talos
Don’t swing at everything
blogs_talos·2026-07-23
CVE-2026-60137 Don’t swing at everything
## Don’t swing at everything
Welcome to this week’s edition of the Threat Source newsletter.
Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance , and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn't limited to closed models anymore.
On the other side of that line, real-world impact hasn't caught up yet and we're living in an artificial buffer zone. For me, defining the “pre-” and “po
Hackernews
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
blogs_hackernews·2026-07-22·CVSS 7.5
CVE-2026-29059 [HIGH] Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.
The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}").
"The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences," according to an advisory published b
Tenable
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
blogs_tenable·2026-07-21
CVE-2026-63030 Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
## Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' own tools.
## Key takeaways
AI coding assistant configuration files, such as settings.json hooks, .cursorrules Cursor MDC rules, and similar harness files, are now explicit targets in supply-chain attacks, not collateral damage.
These files simultaneously sit at the intersection of three trust relationships: The developer trusts them as config, the integrated development environment (IDE) executes them automatic
Tenable
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
blogs_tenable·2026-07-21
CVE-2026-63030 Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
## Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.
## Key Takeaways
The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.
261 issues (18% of all patches) were assigned a critical severity rating
Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches
## Background
On July 21, Oracle released its Critical Patch Update (CPU) for July 2026 , the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this q
Hackernews
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
blogs_hackernews·2026-07-21·CVSS 5.9
CVE-2026-63030 [MEDIUM] WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137 , have been codenamed wp2shell .
"By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public," Ja
Wiz
Exploitation in the Wild of wp2shell
blogs_wiz·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] Exploitation in the Wild of wp2shell
## What are CVE-2026-63030 & CVE-2026-60137?
These vulnerabilities comprise a critical pre-authentication remote code execution (RCE) chain in WordPress Core, dubbed "wp2shell", discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol, and published on July 17th, 2026. This exploit chain allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
## What’s the risk to cloud environments?
Our data indicates that 60% of organizations using WordPress initially had at least one vulnerable instance at the time these CVEs were published, and 25% were exposing a vulnerable server to the Internet. However, this figure is rapidly declining as organizations patch, lowering to 50% and 10% respectively with
Checkpoint
20th July – Threat Intelligence Report
blogs_checkpoint·2026-07-20
CVE-2026-56164 20th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance.
Jscrambler,
Tenable
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
blogs_tenable·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
## wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.
## Key takeaways:
Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations.
Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing w
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
2026-07-17
Published
2026-07-21
Added to CISA KEV
Exploited in the wild