CVE-2026-60137

critical

Description

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

From the Tenable Blog

wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable®
wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable®

Published: 2026-07-20

CVE-2026-63030 and CVE-2026-60137 form the wp2shell pre-auth RCE chain in WordPress Core. Exploitation confirmed. Patches in WordPress 7.0.2 and 6.9.5.

References

https://github.com/DeadExpl0it/wp2shell-poc

https://github.com/mhassani97/cve-2026-63030-lab

https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-

https://github.com/g0d150ne/WP2Shell

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC

https://github.com/rechandra/wp2exp-2026

https://github.com/AdarshThakur14777-cyber/CVE-2026-60137

https://github.com/johnlodan/wp2shell-rce

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/yuag/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/shinthink/CVE-2026-63030

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/mcipekci/wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/ChPratik/Threat_intelligence_Portfolio

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/0xjessie21/wp2shell-checker

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/vulnquest58/PressVector

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/ananay/wp2shell-lab

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ikow/wp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/edenzaraf/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/securelayer7/WordPresShell

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/yoerivegt/wp2shell-poc

https://github.com/zi3lak/wp2shell_scanner

https://github.com/0xWhoknows/wp2shell

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/h4cd0c/wp2shell

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/0xsha/wp2shell

https://github.com/mverschu/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/kulichr/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/ekomsSavior/wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/dinosn/wp2shell-lab

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Icex0/wp2shell-poc

https://github.com/nando0x0a/ThreatForge

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137

Details

Source: Mitre, NVD

Published: 2026-07-17

Updated: 2026-07-29

Named Vulnerability: wp2shellKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 5.4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.78305

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest