2026 Q2 Threat Report: Track the Threats Shaping Enterprise Risk

CVE-2026-60137

How CVE-2026-60137 Turns Unsafe WordPress Queries into SQL Injection Risks

CVSS Gauge
CVSS Needle

Summary

CVE-2026-60137 is a critical SQL injection vulnerability in WordPress caused by improper sanitization of the author__not_in parameter in WP_Query. It affects WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2. Alone, it enables SQL injection. When chained with CVE-2026-63030 (wp2shell), it can lead to unauthenticated remote code execution. Public exploits and active exploitation have been confirmed, and the flaw is listed in CISA’s KEV Catalog. Update WordPress immediately.

Urgent Actions Required

Which Systems Are Vulnerable to CVE-2026-60137?

Technical Overview

How Does the CVE-2026-60137 Exploit Work?

The attack typically follows these steps:

CVE-2026-60137

What Causes CVE-2026-60137?

Vulnerability Root Cause:

The vulnerability is caused by improper sanitization of the author__not_in parameter in WP_Query. When a plugin or theme passes untrusted input to this parameter, the value is not properly sanitized before being used in a database query. As a result, an attacker can inject malicious SQL, potentially exposing or manipulating database data.

How Can You Mitigate CVE-2026-60137?

If immediate patching is delayed or not possible:

  • Identify and update plugins or themes that pass untrusted input to the author__not_in parameter of WP_Query.
  • Configure a web application firewall (WAF) or security plugin to detect and block SQL injection attempts targeting the author__not_in parameter.
  • Monitor logs for unusual database queries or suspicious SQL injection activity.
  • If the vulnerability is part of the wp2shell attack chain, temporarily block anonymous access to the REST batch endpoint (/wp-json/batch/v1 and ?rest_route=/batch/v1) until the site can be updated.

Which Assets and Systems Are at Risk?

Will Patching CVE-2026-60137 Cause Downtime?

Patch application impact: Updating to WordPress 6.8.6, 6.9.5, or 7.0.2 requires a standard WordPress update. Downtime is typically minimal.

How Can You Detect CVE-2026-60137 Exploitation?

Exploitation Signatures:

Look for requests targeting the /wp-json/batch/v1 or ?rest_route=/batch/v1 endpoints, especially if followed by unusual activity such as administrator account creation or malicious plugin uploads.

Indicators of Compromise (IOCs/IOAs):

Alerting Strategy:

Remediation & Response

Build A Stronger Cyber Defense with Real-Time Visibility

      • Understand your cyber terrain across endpoints, servers, and cloud assets
      • Prioritize high-risk assets with multidimensional risk analysis
      • Improve detection and response using integrated XDR and deception technologies
Download the Data SheetSee Fidelis in Action

CVSS Breakdown Table

MetricValue Description
Base Score9.1Critical severity vulnerability
Attack VectorNetworkCan be exploited remotely over the network
Attack ComplexityLowNo special conditions are required for exploitation
Privileges RequiredNoneNo authentication is required
User Interaction NoneDoes not require user involvement
Scope Unchanged The vulnerability affects the vulnerable component
Confidentiality Impact HighMay expose sensitive information through SQL injection
Integrity Impact HighMay allow unauthorized modification of application data
Availability ImpactNoneNo direct impact on service availability

Related Readings

One Platform for All Adversaries

See Fidelis in action. Learn how our fast and scalable platforms provide full visibility, deep insights, and rapid response to help security teams across the World protect, detect, respond, and neutralize advanced cyber adversaries.