cbcvebase.
CVE-2026-60137
published 2026-07-17

CVE-2026-60137: WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow…

PriorityP181medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-04
Exploited in the wild
EPSS
77.97%
99.5th percentile
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Affected

6 ranges
VendorProductVersion rangeFixed in
wordpresswordpress< 7.0.27.0.2
wordpresswordpress>= 6.8 < 6.8.66.8.6
wordpresswordpress>= 6.9 < 6.9.56.9.5
wordpresswordpress>= 6.9.0 < 6.9.56.9.5
wordpresswordpress>= 7.0 < 7.0.27.0.2
wordpresswordpress>= 7.0.0 < 7.0.27.0.2

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck9.1CRITICAL
cisa5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.