PT-2026-60855 · WordPress · Wordpress

·

CVE-2026-60137

·

Published

2026-07-17

·

Updated

2026-07-21

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions 6.8.0 through 6.8.5 WordPress versions 6.9.0 through 6.9.4 WordPress versions 7.0.0 through 7.0.1
Description WordPress Core contains an SQL injection flaw that can be chained with other vulnerabilities to allow unauthenticated remote attackers to execute code on the server and take control of the website. The issue occurs because the WP Query function does not properly sanitize the author not in parameter, which can be exploited when a plugin or theme passes untrusted input to it. This flaw potentially affects over 500 million sites worldwide.
Recommendations Update WordPress to version 6.8.6. Update WordPress to version 6.9.5. Update WordPress to version 7.0.2. As a temporary mitigation, restrict access to the WordPress REST API.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60137

Affected Products

Wordpress