Vulnerability Details CVE-2026-60137
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.04
EPSS Ranking 89.5%
CVSS Severity
CVSS v3 Score 5.9
Proposed Action
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Ransomware Campaign
Unknown
Products affected by CVE-2026-60137
-
cpe:2.3:a:wordpress:wordpress:6.8
-
cpe:2.3:a:wordpress:wordpress:6.8.1
-
cpe:2.3:a:wordpress:wordpress:6.8.2
-
cpe:2.3:a:wordpress:wordpress:6.8.3
-
cpe:2.3:a:wordpress:wordpress:6.8.4
-
cpe:2.3:a:wordpress:wordpress:6.8.5
-
cpe:2.3:a:wordpress:wordpress:6.9
-
cpe:2.3:a:wordpress:wordpress:6.9.1
-
cpe:2.3:a:wordpress:wordpress:6.9.2
-
cpe:2.3:a:wordpress:wordpress:6.9.3
-
cpe:2.3:a:wordpress:wordpress:6.9.4
-
cpe:2.3:a:wordpress:wordpress:7.0
-
cpe:2.3:a:wordpress:wordpress:7.0.1