CVE-2026-60137
KEVCRITICAL 9.1EPSS 78.3%
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
- CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - CVSS v3.1
- 5.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 78.31% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-07-21
- Nuclei
- critical
- Published
- 2026-07-17
- Updated
- 2026-07-29
Proof-of-concept exploits (44)
- Icex0/wp2shell-poc760★ · 2026-08-11
- ekomsSavior/wp2shell8★ · 2026-07-19
- mcipekci/wp2shell15★ · 2026-07-22
- 4minx/CVE-2026-6303010★ · 2026-07-18
- NULL200OK/WP2Shell15★ · 2026-07-18
- securelayer7/WordPresShell12★ · 2026-07-18
- c0gnit00/Wp2Shell0★ · 2026-07-19
- GhostInExile/CVE-2026-63030-Wp2Shell4★ · 2026-07-21
- Crypto-Cat/wp2shell3★ · 2026-07-20
- JohenLastGen-JLG/wp2shell2★ · 2026-07-18
- 4B3R4M4-607D/CVE-2026-63030-POC2★ · 2026-07-19
- johnlodan/wp2shell-rce3★ · 2026-08-04
- yuag/wp2shell0★ · 2026-07-27
- gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc0★ · 2026-07-22
- Giangdurian/CVE-2026-63030-CVE-2026-601370★ · 2026-07-24
- Iqbalx7/wp2shell0★ · 2026-07-20
- SentinelXofficial/sxwp2shell1★ · 2026-07-20
- shinthink/CVE-2026-630300★ · 2026-07-24
- joaovicdev/EXPLOIT-CVE-2026-630301★ · 2026-07-20
- mrx-arafat/CVE-2026-63030-POC0★ · 2026-07-18
- lucifer0xf/wp2shell-Wordpress-TOWN2★ · 2026-07-20
- northsia/CVE-2026-60137-With-Skip-SSL0★ · 2026-07-26
- razureink/cve-2026-63030_60137-wordpress_rce_reproduction0★ · 2026-07-23
- 0xWhoknows/wp2shell1★ · 2026-07-18
- raphy76/wp2shell-poc-fulljs0★ · 2026-07-23
- h4cd0c/wp2shell0★ · 2026-07-18
- sowarma/wp2shell-PoC914★ · 2026-08-20
- TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-0★ · 2026-08-19
- AdarshThakur14777-cyber/CVE-2026-601370★ · 2026-08-03
- DeadExpl0it/wp2shell-poc0★ · 2026-08-21
- AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC0★ · 2026-08-05
- allannjuguna/Wp2Shell0★ · 2026-07-20
- interim-embryoniccell971/wp2shell-Exploit-Waf-Bypass0★ · 2026-08-29
- GMJayy/wp-cve-poc4★ · 2026-08-27
- Ka01nq/WpScc2★ · 2026-08-26
- sahmsec/wp2shell0★ · 2026-08-28
- Dungsocool/CVE-2026-60137_CVE-2026-63030
- codeb0ssx/Ultimate-wp2shell
- 0xBlackash/CVE-2026-630301★ · 2026-07-18
- AnggaTechI/CVE-2026-630301★ · 2026-08-08
- Bhanunamikaze/WP2Shell-CVE-2026-63030-POC0★ · 2026-07-21
- Senanfurkan/wordpress-cve-2026-63030
- b1bek/wp2shell
- edenzaraf/wp2shell