WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
[POC] CVE-2026-60137 — Ultimate-wp2shell
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.
[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-60137
wpsqli full SQLi extractor + dumper for CVE-2026-60137
[POC] GHSA-6vch-q96h-7gc3 — CVE-2026-60137-With-Skip-SSL
Adding --insecure to skip ssl
[POC] CVE-2026-63030 — CVE-2026-63030-CVE-2026-60137-wp2shell-poc
CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc
[POC] CVE-2026-60137 — wp2shell-poc
Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030
[POC] CVE-2026-60137 — Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)
[POC] CVE-2026-60137 — abdal-cve-2026-60137
Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. Developed by Ebrahim Shafiei (EbraSha) for vulnerability assessment, security research, and authorized penetration testing.
[POC] CVE-2026-60137 — wp2shell-poc
wp2shell (CVE-2026-60137 / CVE-2026-63030)
[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-60137-WordPress-Core-SQL-Injection-PoC
Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.
[POC] CVE-2026-60137 — wp2shell
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.
PoC: Wp2shell-ioc-scanner
Defensive WordPress incident-response plugin for the "wp2shell" attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin IOCs and deletes a selected account in a controlled, logged way. Does not remove malware.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free