Feed/CVE-2026-60137
CVE-2026-60137MEDIUMCVSS 5.9CISA KEV: Actively Exploited

CVE-2026-60137

Published Jul 17, 2026·Updated Jul 29, 2026

NVD Description

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Public Exploits & PoCs11 found

[POC] CVE-2026-60137 — Ultimate-wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.

4

[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-60137

wpsqli full SQLi extractor + dumper for CVE-2026-60137

[POC] GHSA-6vch-q96h-7gc3 — CVE-2026-60137-With-Skip-SSL

Adding --insecure to skip ssl

[POC] CVE-2026-63030 — CVE-2026-63030-CVE-2026-60137-wp2shell-poc

CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc

[POC] CVE-2026-60137 — wp2shell-poc

Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030

[POC] CVE-2026-60137 — Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

[POC] CVE-2026-60137 — abdal-cve-2026-60137

Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. Developed by Ebrahim Shafiei (EbraSha) for vulnerability assessment, security research, and authorized penetration testing.

[POC] CVE-2026-60137 — wp2shell-poc

wp2shell (CVE-2026-60137 / CVE-2026-63030)

[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-60137-WordPress-Core-SQL-Injection-PoC

Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.

[POC] CVE-2026-60137 — wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.

PoC: Wp2shell-ioc-scanner

Defensive WordPress incident-response plugin for the "wp2shell" attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin IOCs and deletes a selected account in a controlled, logged way. Does not remove malware.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free