← Back to browse · API

CVE-2026-60137

Severity
MEDIUM
CVSS
5.9
EPSS
0.79029
Risk score
76.26
CISA KEV
Yes
PoC
Yes
Published
2026-07-17
Modified
2026-07-29
First seen
2026-08-05
Aliases
EUVD-2026-45279
Products
WordPress Foundation:WordPress 6.8.0 <6.8.6, WordPress Foundation:WordPress 6.9.0 <6.9.5, WordPress Foundation:WordPress 7.0.0 <7.0.2, WordPress:Core, debian, linux, wordpress:wordpress
Sources
nvd CVE-2026-60137
euvd EUVD-2026-45279
github 820531e5ed866c981815a3b3|CVE-2026-60137
github f22bd718c73e64be60e001ce|CVE-2026-60137
github a254472902104a0f3e520a47|CVE-2026-60137
github bf14aa225a46de04442bee1f|CVE-2026-60137
github ed2d12289643dd90d96e6b07|CVE-2026-60137
github cd2e5ce1eb0cf031f7826abe|CVE-2026-60137
packetstorm 807baa415c5a6bc5d3968b27|CVE-2026-60137
packetstorm 8b56a812398f6e3cc46446d6|CVE-2026-60137
cisa.gov CVE-2026-60137
packetstorm cea991c39c72ace41c38b3af|CVE-2026-60137
packetstorm 0ab3d95560ca291f975dd446|CVE-2026-60137
packetstorm 16837ebf9f28e480d9f7752c|CVE-2026-60137
packetstorm 1f2fd4f4866301e10f1d830f|CVE-2026-60137
packetstorm a5f1e41a64bb49e6cd43efcf|CVE-2026-60137

Description

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

References