WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Published: 2026-07-20
CVE-2026-63030 and CVE-2026-60137 form the wp2shell pre-auth RCE chain in WordPress Core. Exploitation confirmed. Patches in WordPress 7.0.2 and 6.9.5.
https://latesthackingnews.com/2026/07/26/wp2shell-vulnerability-wordpress-rce/
https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/
Published: 2026-07-17
Updated: 2026-07-29
Named Vulnerability: wp2shellKnown Exploited Vulnerability (KEV)
Base Score: 5.4
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N
Severity: Medium
Base Score: 9.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: Critical
EPSS: 0.731
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest