CVE-2026-60137

CRITICALPre-NVD 9.19.1
EchelonGraph scoreHIGH confidence

Score elevated to 9.1 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2026-07-21), indicating real-world exploitation has been confirmed by US federal agencies. CISA-ADP (Vulnrichment) CVSS v3.1 baseline 9.1 retained for reference (NVD's own analysis pending). Confidence: HIGH.

Triggered by: CISA KEV (actively exploited)
Sources: cisa-adp, cisa_kev, epss
Trending — KEV-added this weekExploited in the wild
9.1
EchelonGraph verdictPatch nowTreat as an emergency — this is being exploited.
  • Actively exploited in the wild (CISA-KEV)
CISA-KEV: ExploitedEPSS: 20%CVSS: 9.1Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

CVSS v3
9.1
EG Score
9.1(high)
EPSS
97.2%
KEV
⚠ Exploited

Published

July 17, 2026

Last Modified

July 22, 2026

Advisory Details (2)

Auto-updated Jul 17, 2026
Patch available. Sources: github.
generic

WordPress 7.0.2 Release – WordPress News

https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
github Patch Available

Facilitated SQL injection vulnerability in the `author__not_in` parameter of `WP_Query` · Advisory · WordPress/wordpress-develop · GitHub

https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 25× in last 7d / 25× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-22 14:08 UTCEPSS rescore
  2. 2026-07-22 14:08 UTCEPSS rescore
  3. 2026-07-22 05:22 UTCEG score recompute 0.10
  4. 2026-07-22 05:20 UTCNVD updateCVSS v3 → 9.1 · severity → CRITICAL
  5. 2026-07-21 20:14 UTCEG score recompute 0.10
  6. 2026-07-21 20:13 UTCMITRE cvelistV5CVSS v3 → 5.9 · severity → MEDIUM
  7. 2026-07-21 17:19 UTCEG score recompute 0.10
  8. 2026-07-21 17:18 UTCNVD updateCVSS v3 → 9.1 · severity → CRITICAL
  9. 2026-07-21 16:01 UTCEG score recompute 0.10
  10. 2026-07-21 15:58 UTCMITRE cvelistV5CVSS v3 → 5.9 · severity → MEDIUM
  11. 2026-07-21 15:25 UTCEPSS rescore
  12. 2026-07-21 15:25 UTCEPSS rescore
  13. 2026-07-21 14:40 UTCEG score recompute
  14. 2026-07-21 14:37 UTCCISA KEV update
  15. 2026-07-20 17:08 UTCEPSS rescore
  16. 2026-07-19 14:31 UTCEPSS rescore
  17. 2026-07-19 02:29 UTCEPSS rescore
  18. 2026-07-18 06:05 UTCEG score recompute 3.20
  19. 2026-07-18 06:02 UTCNVD updateCVSS v3 → 9.1 · severity → CRITICAL
  20. 2026-07-18 04:20 UTCEG score recompute 3.20
  21. 2026-07-18 04:19 UTCMITRE cvelistV5CVSS v3 → 5.9 · severity → MEDIUM
  22. 2026-07-17 20:20 UTCEG score recompute 9.10
  23. 2026-07-17 20:19 UTCMITRE cvelistV5CVSS v3 → 9.1 · severity → CRITICAL
  24. 2026-07-17 19:25 UTCEG score recompute
  25. 2026-07-17 19:24 UTCMITRE cvelistV5first tracked

Publicly available exploits

(1 reference)

Working exploit code is in the public domain (1 GitHub PoC). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.

  • GitHub PoCcodeb0ssx/Ultimate-wp2shell
    First seen Jul 18, 2026

    wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.

    Open source ↗

Frequently asked(6)

What is CVE-2026-60137?
CVE-2026-60137 is a critical vulnerability published on July 17, 2026. WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the authornotin parameter of WPQuery, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
When was CVE-2026-60137 disclosed?
CVE-2026-60137 was first published in the National Vulnerability Database on July 17, 2026, with the most recent update on July 22, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-60137 actively exploited?
Yes. CISA added CVE-2026-60137 to the Known Exploited Vulnerabilities catalog on July 21, 2026, affecting WordPress Core. KEV listing indicates confirmed exploitation in the wild; this CVE warrants immediate patching attention.
What is the CVSS score of CVE-2026-60137?
CVE-2026-60137 has a CVSS v3.1 base score of 9.1 (CISA-ADP / Vulnrichment enrichment; NVD's own analysis pending).
Which products are affected by CVE-2026-60137?
CVE-2026-60137 affects WordPress Core. The full affected-products list, including version ranges and fixed versions, is shown in the Affected Packages section of this page.
How do I remediate CVE-2026-60137?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-60137, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-60137

Explore →

Is Your Infrastructure Affected by CVE-2026-60137?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.