๐Ÿ” CVE Alert

CVE-2026-60137

MEDIUM 5.9 โš ๏ธ CISA KEV

WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

CVSS Score
5.9
EPSS Score
78.0%
EPSS Percentile
100th

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Vendor wordpress
Product wordpress
Ecosystems
Industries
WebMedia
Published Jul 17, 2026
Last Updated Jul 29, 2026
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for wordpress wordpress

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-60137.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

WordPress / WordPress
6.8.0 < 6.8.6 6.9.0 < 6.9.5 7.0.0 < 7.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf wordpress.org: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137

Credits

TF1T dtro haongo WordPress Security Team