// CVE

CVE-2026-60137

Medium 5.9 Exploited (KEV)

WordPress Core

5.9CVSS
73%EPSS
YesCISA KEV

Summary

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Published: 2026-07-17 · In KEV since: 2026-07-21

Analysis

🔴 Critical — actively exploited

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, with high complexity.

Impact: Confidentiality high · Integrity none · Availability none.

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

The vector encodes how it's exploited (translated above, in the analysis). Break it down in the CVSS tool →

← Back to the Threat Radar

Sources: CISA KEV · EPSS · FIRST.org · NVD. Analysis derived from the CVSS vector and exploitation status (no AI). Informational; always verify against the vendor's official advisory.