Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4152 articles · 221978 vulns · 36/41 feeds (7d)
← Back to list
5.9
CVE-2026-60137KEVEXPLOITEDPATCHED
wordpress · wordpress

WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

Description

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Affected Products

VendorProductVersions
wordpresswordpress6.8.0, 6.9.0, 7.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcewordpresscert_advisory90%

References

  • https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf(vdb-entry, technical-description)
  • https://wordpress.org/news/2026/07/wordpress-7-0-2-release/(release-notes, vendor-advisory)

Related News (20 articles)

Tier C
Rapid7 Blog27d ago
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
→ No new info (linked only)
Tier B
CERT-FR45d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier B
CERT-FR59d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier C
Cisco Talos62d ago
Don’t swing at everything
→ No new info (linked only)
Tier E
Reddit r/cybersecurity64d ago
WP2Shell: Hands-On Lab Reproducing the Pre-Auth WordPress Core RCE
→ No new info (linked only)
Tier D
BleepingComputer64d ago
Critical wp2shell WordPress flaws exploited to install webshells
→ No new info (linked only)
Tier D
Heise Security65d ago
WordPress-Lücke „wp2shell“ wird angegriffen
→ No new info (linked only)
Tier D
The Hacker News65d ago
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
→ No new info (linked only)
Tier D
Dark Reading65d ago
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
→ No new info (linked only)
Tier B
CCCS Canada65d ago
WordPress security advisory (AV26-723)
→ No new info (linked only)
Tier B
BSI Advisories66d ago
[NEU] [kritisch] WordPress: Mehrere Schwachstellen ermöglichen Codeausführung
→ No new info (linked only)
Tier E
Reddit r/cybersecurity66d ago
WP2Shell WordPress Vulnerabilities Exploited in the Wild
→ No new info (linked only)
Tier D
SecurityWeek66d ago
WP2Shell WordPress Vulnerabilities Exploited in the Wild
→ No new info (linked only)
Tier B
CERT-FR66d ago
Multiples vulnérabilités dans WordPress (20 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR66d ago
Multiples vulnérabilités dans WordPress (20 juillet 2026)
→ No new info (linked only)
Tier D
BleepingComputer67d ago
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
→ No new info (linked only)
Tier D
Help Net Security68d ago
Two new high severity WordPress vulnerabilities, patch immediately!
→ No new info (linked only)
Tier E
Reddit r/cybersecurity68d ago
Technical analysis of wp2shell: The latest WordPress Core pre-auth RCE chain
→ No new info (linked only)
Tier D
Heise Security68d ago
„wp2shell“: Kritische WordPress-Lücke erlaubt Codeeinschleusung über API
→ No new info (linked only)
Tier C
VulDB68d ago
CVE-2026-60137 | WordPress up to 6.8.5/6.9.4/7.0.1 WP_Query sql injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.9 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
6.8.66.9.57.0.2
PublishedJul 17, 2026
Last enriched64d agov10
Tags
cvss:criticalremote-attackchain-exploitcodeinjectionapi-basedunauthenticated-rcewp2shellrcepre-authbatch-route-confusionrest-apicert-frpublic-poccert-fr-avis-20260720sql-injectionwebshell-deploymentrest-api-abusephp-backdoorplugin-upload-abuselfirogue-admin-accounts
Trending Score3
Source articles20
Independent13
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-87902EXPKEV
CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph
Trending: 136
CRITICALCVE-2026-63030EXPKEV
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
Trending: 4
HIGHCVE-2026-65640
CVE-2026-65640: WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level
Trending: 1
NONECVE-2026-64638
CVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
Trending: 1
CRITICALCVE-2026-6382EXP
Multiple elFinder Plugins - Authenticated OS Command Injection

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Added to CISA KEV
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: severity, cvssEstimate, affectedVersions, tags
Jul 17, 2026
Updated: tags
Jul 18, 2026
Updated: severity, cvssEstimate, exploitAvailable, activelyExploited, tags
Jul 18, 2026
Updated: description, affectedVersions, tags
Jul 18, 2026
Updated: affectedVersions, tags
Jul 20, 2026
Updated: affectedVersions
Jul 20, 2026
Updated: affectedVersions, tags
Jul 20, 2026
Updated: iocs
Jul 21, 2026
Updated: cweIds, tags
Jul 21, 2026
Actively Exploited
Jul 29, 2026
Exploit Available
Jul 29, 2026
Patch Available
Jul 29, 2026

Version History

v10
Last enriched 64d ago
v10Tier D64d ago

Updated severity from MEDIUM to CRITICAL and CVSS from 5.9 to 9.8; added CWE-89 (SQL Injection); added MITRE ATT&CK techniques T1190, T1190.002, T1505.003, T1505.004; added new tags documenting observed attack techniques including webshell deployment, plugin upload abuse, LFI, and rogue admin account creation.

cweIdstags
via BleepingComputer
v9Tier D65d ago

Updated CVSS score from 9.1 to 9.8 for the complete vulnerability chain as assessed by BSI; added IoC information about persistent webshells being deployed in active attacks.

iocs
via Heise Security
v8Tier B66d ago

Added WordPress 7.1.x before 7.1-beta2 to affected versions based on CERT-FR advisory, and added CERT-FR advisory reference tag.

affectedVersionstags
via CERT-FR
v7Tier B66d ago

Added WordPress 7.1.x versions (up to 7.1 beta2) to affected versions list, expanding the scope beyond the currently recorded 7.1.0.

affectedVersions
via CERT-FR
v6Tier B66d ago

Added WordPress 7.1.x versions (before 7.1 beta2) to affected versions list and added tags for CERT-FR advisory and public proof of concept availability.

affectedVersionstags
via CERT-FR
v5Tier D67d ago

Added technical details about CVE-2026-63030 REST API batch-route confusion vulnerability used in wp2shell RCE chain, expanded affected versions list, and added MITRE ATT&CK techniques.

descriptionaffectedVersionstags
via BleepingComputer
v4Tier D68d ago

Updated severity from MEDIUM to CRITICAL, CVSS score from 5.9 to 9.1, marked exploit as available and actively exploited, and added tags reflecting the chained vulnerability enabling unauthenticated code injection.

severitycvssEstimateexploitAvailableactivelyExploitedtags
via Heise Security
v3Tier D68d ago

Updated severity to CRITICAL and CVSS score from 5.9 to 9.1; marked as actively exploited; added tag for chained exploit and code injection capability.

tags
via Heise Security
v2Tier C68d ago

Updated severity to CRITICAL, added CVE ID (CVE-2026-60137), refined affected versions to include all point releases up to 6.8.5/6.9.4/7.0.1, and estimated CVSS at 9.0 for critical remote SQL injection vulnerability.

severitycvssEstimateaffectedVersionstags
via VulDB
v168d ago

Initial creation