CVE-2026-60137

medium

Description

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

References

https://github.com/DeadExpl0it/wp2shell-poc

https://github.com/mhassani97/cve-2026-63030-lab

https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-

https://github.com/g0d150ne/WP2Shell

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC

https://github.com/rechandra/wp2exp-2026

https://github.com/AdarshThakur14777-cyber/CVE-2026-60137

https://github.com/johnlodan/wp2shell-rce

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/yuag/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/shinthink/CVE-2026-63030

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/mcipekci/wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/ChPratik/Threat_intelligence_Portfolio

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/0xjessie21/wp2shell-checker

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/vulnquest58/PressVector

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/ananay/wp2shell-lab

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ikow/wp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/edenzaraf/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/securelayer7/WordPresShell

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/yoerivegt/wp2shell-poc

https://github.com/zi3lak/wp2shell_scanner

https://github.com/0xWhoknows/wp2shell

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/h4cd0c/wp2shell

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/0xsha/wp2shell

https://github.com/mverschu/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/kulichr/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/ekomsSavior/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/dinosn/wp2shell-lab

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Icex0/wp2shell-poc

https://github.com/nando0x0a/ThreatForge

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45279

Details

Source: Mitre, NVD

Published: 2026-07-17

Updated: 2026-10-08

Named Vulnerability: wp2shellKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 5.4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.9

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.05323

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest