{"cve":{"cve_id":"CVE-2026-60137","is_kev":true,"kev_date_added":"2026-07-21","kev_vendor_project":"WordPress","kev_product":"Core","kev_vulnerability_name":"WordPress Core SQL Injection Vulnerability","kev_short_description":"WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.","kev_required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due_date":"2026-08-04","kev_known_ransomware":false,"kev_notes":"https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-60137","kev_cwes":["CWE-89"],"epss_score":0.78305,"epss_percentile":0.99544,"epss_as_of":"2026-08-26","description":"WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.","published_at":"2026-07-17T19:14:12.159000Z","last_modified_at":"2026-07-29T20:17:06.270000Z","cvss_v3_score":5.9,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cvss_v3_severity":"MEDIUM","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":false,"ssvc_technical_impact":"total","cwes":["CWE-89"],"nvd_references":["https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf","https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":true,"trended_number_one":false,"trending_peak_score":0.6259445759452174,"trending_peak_rank":4,"started_trending_at":"2026-07-28T01:04:53.289797Z","trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-07-17T19:35:28.549450Z","updated_at":"2026-07-31T08:23:04.751787Z"},"effective_severity":"MEDIUM","badges":["kev","news","epss"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"H","value_label":"High"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"N","value_label":"None"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"wordpress","vendor_name":"WordPress","product_slug":"wordpress","product_name":"WordPress","version_start":"6.8.0","version_start_inclusive":true,"version_end":"6.8.6","version_end_inclusive":false,"cpe23_uri":"cve5:wordpress:wordpress:6.8.0:6.8.6"},{"vendor_slug":"wordpress","vendor_name":"WordPress","product_slug":"wordpress","product_name":"WordPress","version_start":"6.9.0","version_start_inclusive":true,"version_end":"6.9.5","version_end_inclusive":false,"cpe23_uri":"cve5:wordpress:wordpress:6.9.0:6.9.5"},{"vendor_slug":"wordpress","vendor_name":"WordPress","product_slug":"wordpress","product_name":"WordPress","version_start":"7.0.0","version_start_inclusive":true,"version_end":"7.0.2","version_end_inclusive":false,"cpe23_uri":"cve5:wordpress:wordpress:7.0.0:7.0.2"},{"vendor_slug":"wordpress","vendor_name":"WordPress","product_slug":"wordpress","product_name":"WordPress","version_start":"6.8","version_start_inclusive":true,"version_end":"6.8.6","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"}],"exploit_refs":[],"news":[{"id":727,"source":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/","title":"Critical wp2shell WordPress flaws exploited to install webshells","summary":"Hackers are exploiting the \"wp2shell\" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]","thumbnail_url":null,"author":"Bill Toulas","published_at":"2026-07-21T16:41:50Z","fetched_at":"2026-07-21T17:08:10.336265Z","trending_score":4.415682218476516e-6,"cve_ids":["CVE-2026-60137"]},{"id":715,"source":"The Hacker News","url":"https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html","title":"WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning","summary":"Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.\n\nThe two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.\n\n\"By the early hours of Saturday morning (UTC), successful exploitation was already well","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4qOga3YGcLZ3JclK_mkOkQ-pRmQowUUqu6Hp3fj1QTmsNuuhkSj4OiFqgAtL7e6yeGkv-K1jC0v4bRayI40oDQ8UMeYishuNzRap3E5RYmIEbjRbmq-uAk4iWKWwIfMdNi6owJrVWE_3fcWzj5lZgVm9P96ddcqghwnp3rGx3pM3N6hck6UiaFUgVRbtC/s1600/wordpress-ex.jpg","author":"info@thehackernews.com (The Hacker News)","published_at":"2026-07-21T08:59:30Z","fetched_at":"2026-07-21T09:38:10.529381Z","trending_score":3.6467889903443363e-6,"cve_ids":["CVE-2026-60137"]},{"id":707,"source":"Dark Reading","url":"https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover","title":"'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover","summary":"Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.","thumbnail_url":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltb1df0898ba4c4a15/6a5e837c6c884d291eb9cdc9/wordpress_Silver_Wings_shutterstock.jpg?width=720&quality=80&disable=upscale","author":"Jai Vijayan","published_at":"2026-07-20T21:38:18Z","fetched_at":"2026-07-20T22:23:10.908340Z","trending_score":2.8373970847350033e-6,"cve_ids":["CVE-2026-60137"]}],"references":[{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://wordpress.org/news/2026/07/wordpress-7-0-2-release/","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2026-07-17T19:14:12.159000Z","label":"CVE published","source":null},{"type":"ssvc_changed","at":"2026-07-17T20:36:28.548823Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-07-17T20:36:28.548823Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-07-17T20:36:28.548823Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-07-17T20:36:28.548823Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-07-17T20:36:28.548823Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-07-17T20:36:28.548823Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-07-18T05:36:28.551688Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-07-18T05:36:28.551688Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-07-18T05:36:28.551688Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"first_article","at":"2026-07-20T21:38:18Z","label":"First news coverage","source":"Dark Reading"},{"type":"cisa_reported","at":"2026-07-21T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"ssvc_changed","at":"2026-07-21T16:41:10.176619Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"started_trending","at":"2026-07-28T01:04:53.289797Z","label":"Started trending","source":null},{"type":"ssvc_changed","at":"2026-07-29T21:04:23.267502Z","label":"SSVC decision revised","source":"vulnrichment"}]}