Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N N U H N N 5.9 .7310 99.4 YES
AFFECTED
Product Versions Fixed
WordPress 6.8.0 – —
TIMELINE
Jul 17 Reserved by WPScan
Jul 21 Added to CISA KEV, remediation due 2026-08-04
Jul 21 Published (CNA: WPScan)
Aug 5 DUE DATE PASSED — CVE-2026-60137 (WordPress). CISA remediation deadline was August 4, 2026; still in catalog.
Description
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| July 17, 2026 | Reserved | Reserved by WPScan |
| July 21, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-08-04 |
| July 21, 2026 | Published | Published (CNA: WPScan) |
| August 5, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-60137 (WordPress). CISA remediation deadline was August 4, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| WordPress | WordPress | — | 6.8.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-60137 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.