CVE-2026-60137
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
CVSS Score
5.9
EPSS Score
78.0%
EPSS Percentile
100th
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
| Vendor | wordpress |
| Product | wordpress |
| Ecosystems | |
| Industries | WebMedia |
| Published | Jul 17, 2026 |
| Last Updated | Jul 29, 2026 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for wordpress wordpress
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-60137.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
WordPress / WordPress
6.8.0 < 6.8.6 6.9.0 < 6.9.5 7.0.0 < 7.0.2
References
Credits
TF1T dtro haongo WordPress Security Team