SQL Injection Vulnerability in WordPress Core Affecting Multiple Versions
CVE-2026-60137
Key Information:
Badges
What is CVE-2026-60137?
CVE-2026-60137 is a critical SQL injection vulnerability found in the WordPress Core, impacting multiple versions prior to 6.8.6, 6.9.5, and 7.0.2. WordPress, a widely used content management system, allows users to create and manage websites effortlessly. This vulnerability arises from improper sanitization of the author__not_in parameter in the WP_Query class, which can lead to SQL injection attacks if untrusted inputs are passed through plugins or themes. Attackers could exploit this flaw to gain unauthorized access to databases, execute arbitrary SQL commands, and manipulate sensitive information.
The implications of this vulnerability can be dire for organizations that rely on WordPress for their web presence, as it can compromise the integrity and confidentiality of their data. With an open-source framework like WordPress being extensively deployed across various sectors, the potential for mass exploitation is significant, impacting not just individual sites but potentially the wider ecosystem.
Potential impact of CVE-2026-60137
-
Data Breaches: Exploitation of this vulnerability could allow attackers to access and exfiltrate sensitive information from the database, including user data, passwords, and personal identifiable information, thereby leading to severe data breaches.
-
Website Compromise: Successful SQL injection attacks could enable hackers to manipulate or delete critical website data, leading to service disruption, defacement, or unauthorized changes to site content, severely damaging an organization's reputation and reliability.
-
Increased Ransomware Risks: The ability to execute arbitrary SQL commands can be leveraged by attackers to install malicious scripts and backdoors, potentially paving the way for ransomware deployment and further malicious activities within an organization's IT infrastructure.
CISA has reported CVE-2026-60137
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-60137 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
WordPress 6.8.0 < 6.8.6
WordPress 6.9.0 < 6.9.5
WordPress 7.0.0 < 7.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Hackers Exploit Newly Patched WordPress Vulnerabilities
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.
3 weeks ago
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and
3 weeks ago
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.
3 weeks ago
References
EPSS Score
79% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🦅
CISA Reported
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by It Security News
Vulnerability published
Vulnerability Reserved