CVE Details

CVE-2026-60137 WordPress Core SQL Injection Vulnerability
Published: 2026-07-21 CVSS: 5.9 MEDIUM Product: WordPress Core Due Date: 2026-08-04

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • GhostTroops/TOP • ⭐ 733 • 2022-03-19 • Conf: 90.0%
  • TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things
  • Icex0/wp2shell-poc • ⭐ 455 • 2026-07-17 • Conf: 95.0%
  • wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
  • sergiointel/wp2shell-poc • ⭐ 91 • 2026-07-17 • Conf: 98.0%
  • Stock vulnerable wordpress RCE poc for wp2shell.
  • 0xsha/wp2shell • ⭐ 57 • 2026-07-18 • Conf: 93.0%
  • CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 5.9
  • Severity: MEDIUM
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-60137
cveMetadata > assignerOrgId 1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName WPScan
cveMetadata > dateReserved 2026-07-17T17:17:24.479Z
cveMetadata > datePublished 2026-07-17T19:14:12.159Z
cveMetadata > dateUpdated 2026-07-21T15:45:18.100Z
containers > cna > providerMetadata > orgId 1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81
containers > cna > providerMetadata > shortName WPScan
containers > cna > providerMetadata > dateUpdated 2026-07-18T04:13:49.003Z
containers > cna > title WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-89 SQL Injection
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > affected > 0 > vendor WordPress
containers > cna > affected > 0 > product WordPress
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version 6.8.0
containers > cna > affected > 0 > versions > 0 > lessThan 6.8.6
containers > cna > affected > 0 > versions > 0 > versionType semver
containers > cna > affected > 0 > versions > 1 > status affected
containers > cna > affected > 0 > versions > 1 > version 6.9.0
containers > cna > affected > 0 > versions > 1 > lessThan 6.9.5
containers > cna > affected > 0 > versions > 1 > versionType semver
containers > cna > affected > 0 > versions > 2 > status affected
containers > cna > affected > 0 > versions > 2 > version 7.0.0
containers > cna > affected > 0 > versions > 2 > lessThan 7.0.2
containers > cna > affected > 0 > versions > 2 > versionType semver
containers > cna > affected > 0 > defaultStatus unaffected
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
containers > cna > references > 0 > url https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
containers > cna > references > 0 > tags > 0 vdb-entry
containers > cna > references > 0 > tags > 1 technical-description
containers > cna > references > 1 > url https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
containers > cna > references > 1 > tags > 0 release-notes
containers > cna > references > 1 > tags > 1 vendor-advisory
containers > cna > metrics > 0 > cvssV3_1 > version 3.1
containers > cna > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
containers > cna > metrics > 0 > cvssV3_1 > baseScore 5.9
containers > cna > metrics > 0 > cvssV3_1 > baseSeverity MEDIUM
containers > cna > credits > 0 > lang en
containers > cna > credits > 0 > value TF1T
containers > cna > credits > 0 > type finder
containers > cna > credits > 1 > lang en
containers > cna > credits > 1 > value dtro
containers > cna > credits > 1 > type finder
containers > cna > credits > 2 > lang en
containers > cna > credits > 2 > value haongo
containers > cna > credits > 2 > type finder
containers > cna > credits > 3 > lang en
containers > cna > credits > 3 > value WordPress Security Team
containers > cna > credits > 3 > type coordinator
containers > cna > source > discovery EXTERNAL
containers > cna > x_generator > engine WPScan CVE Generator
containers > adp > 0 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 0 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseScore 9.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > adp > 0 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
containers > adp > 0 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 0 > metrics > 0 > cvssV3_1 > availabilityImpact NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 0 > metrics > 1 > other > type ssvc
containers > adp > 0 > metrics > 1 > other > content > id CVE-2026-60137
containers > adp > 0 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 1 > other > content > options > 1 > Automatable yes
containers > adp > 0 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 1 > other > content > version 2.0.3
containers > adp > 0 > metrics > 1 > other > content > timestamp 2026-07-21T15:45:09.401257Z
containers > adp > 0 > metrics > 2 > other > type kev
containers > adp > 0 > metrics > 2 > other > content > dateAdded 2026-07-21
containers > adp > 0 > metrics > 2 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137
containers > adp > 0 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137
containers > adp > 0 > references > 0 > tags > 0 government-resource
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > cweId CWE-89
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > description CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-07-21T15:45:18.100Z