Vulnerability threat dossier

CVE-2026-60137

wordpresswordpress

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

VTP deterministic threat43.2of 100 · CVSS excluded

VTP analyst assessment

WordPress Core SQL injection with known exploitation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityMEDIUM
AI confidence95%
Public exploitation · VTP factKEV

Assessment

CVE-2026-60137 affects WordPress query handling when a plugin or theme passes untrusted input to author__not_in. ENISA lists the flaw as known exploited, and CISA KEV also records global exploitation. Successful SQL injection could expose database content.

Why it matters

  • The vulnerable parameter is reachable only through custom plugin or theme use of untrusted input.
  • A Metasploit-related publication indicates public technical coverage.

Evidence

3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The mapped reporting does not identify affected deployments or a specific campaign against this CVE.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use affected WordPress releases, update to 6.8.6, 6.9.5, 7.0.2, or later as applicable.

AI baseline history (4)
  1. BASELINE ASSESSED
    WordPress Core SQL injection with known exploitationgpt-5.6-terra · low
  2. BASELINE ASSESSED
    WordPress core SQL injectiongpt-5.6-terra · low
  3. BASELINE ASSESSED
    Conditional WordPress WP_Query SQL injectiongpt-5.6-sol · high
  4. BASELINE ASSESSED
    WordPress WP_Query SQL injectiongpt-5.6-sol · high
Technical severityMEDIUMCVSS 5.9 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0693th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.06; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EPSS MATERIAL DECREASEEPSS changed materially from 0.78 to 0.06
RESEARCH PUBLICATIONNew technical research
RESEARCH PUBLICATIONNew technical research
RESEARCH PUBLICATIONNew technical research
ACTIVE EXPLOITATIONENISA EU KEV entry added
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

5publications detected
5underlying evidence chains

3 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-60137ACTIVE
Evidence
04

Event history

Threat timeline

  1. 18:3624 Sept
    EPSS MATERIAL DECREASE

    EPSS changed materially from 0.78 to 0.06

    Predictive context changed; this is not exploitation evidence.

  2. 14:5728 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-60137.

  3. 21:2714 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-60137.

  4. 18:0023 Jul
    RESEARCH PUBLICATION

    New technical research

    Cisco Talos published evidence linked to CVE-2026-60137.

  5. 00:0021 Jul
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. This is public intelligence, not a VTP sensor observation.

  6. 00:0021 Jul
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]

CVE-2022-0847CVE-2023-54391CVE-2026-34908CVE-2026-34909CVE-2026-34910CVE-2026-54569CVE-2026-56271CVE-2026-60004CVE-2026-60137CVE-2026-63030CVE-2026-7273CVE-2026-79756
Separate evidence group
Original

Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

CVE-2026-0265CVE-2026-16232CVE-2026-19681CVE-2026-21820CVE-2026-3576CVE-2026-56274CVE-2026-59774CVE-2026-60137CVE-2026-63030CVE-2026-66066CVE-2026-6826CVE-2026-9082CVE-2026-9198
Separate evidence group
Original

Metasploit Wrap Up: Lot of summer shells and fit http profiles

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: *Nyan Nyan Nyan Nyan Nyan Nyan.* New module content (13) Ray Dashboard Logs API Path Traversal Author: Richard Howe <rhowe425> Type: Auxiliary Pull request: #21681 contributed by rmhowe425 Path: `gather/ray_dashboard_logs_api_path_traversal` Description: This adds an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of local directories. There is currently no CVE assigned to this vulnerability. Issuance is pending with MITRE. Pterodactyl Panel CVE-2025-49132 Remote Code Execution Authors: 0xtensho and jheysel-r7 Type: Exploit Pull request: #21452 contributed by jheysel-r7 Path: `linux/http/pterodactyl_locales_locale_json` AttackerKB reference: CVE-2025-49132 Description: This adds a module which exploits a vulnerability in Pterodactyl Panel before version 1.11.11 that allows unauthenticated remote code execution through improper handling of locale file operations. The vulnerability, CVE-2025-49132, exists in the locale.json endpoint which allows path traversal and arbitrary file creation. This combination of capabilities results in remote code execution in the context of the user running the web server. SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution Authors: Deral Heiland, Rapid7 Vulnerability Research, and Ryan Emmons Type: Exploit Pull request: # 21678 contributed by dheiland-r7(https://github.com/dheiland-r7) Path: `linux/http/sonicwall_sma1000_wsproxy_rce` AttackerKB reference: CVE-2026-15409 Description: This adds a new exploit module for CVE-2026-15409, a Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 WorkPlace wsproxy service. Fragnesia LPE (CVE-2026-46300) Authors: William Bowling and msutovsky-r7 Type: Exploit Pull request: #21456 contributed by msutovsky-r7 Path: linux/local/cve_2026_46300_fragnesia AttackerKB reference: CVE-2026-46300 Description: This adds a local module for the Fragnesia exploit which is a page-cache replacement vulnerability in the Linux kernel's XFRM (IPsec) subsystem, tracked as CVE-2026-46300. Ghost CMS Remote Code Execution Authors: Cristian-Alexandru Staicu and Maksim Rogov Type: Exploit Pull request: #21234 contributed by vognik Path: multi/http/ghostcms_auth_rce_cve_2026_29053 AttackerKB reference: CVE-2026-22594 Description: This adds an exploit module for Ghost CMS (CVE-2026-29053) that achieves remote code execution by uploading a malicious theme. Ghost's theme renderer evaluates untrusted JSONPath expressions through the {{#get}} helper, letting the module inject and trigger arbitrary code once a theme is uploaded and activated. You'll need valid admin or staff credentials to authenticate. Joomla Content Editor Unauthenticated File Upload RCE Authors: David Jardin, Uwe Flottemesch, and ispyispyispy Type: Exploit Pull request: #21615 contributed by 15py15py15py Path: multi/http/joomla_com_jce_unauth_file_upload_rce AttackerKB reference: CVE-2026-48907 Description: This adds a new exploit module for CVE-2026-48907, an unauthenticated arbitrary profile creation vulnerability in the JCE (Joomla Content Editor) extension for Joomla!. The profiles.import task fails t

CVE-2025-49132CVE-2026-15409CVE-2026-22594CVE-2026-27760CVE-2026-29053CVE-2026-33017CVE-2026-3891CVE-2026-46300CVE-2026-48907CVE-2026-52806CVE-2026-60137CVE-2026-63030
Separate evidence group
Original

Don’t swing at everything

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

CVE-2026-60137CVE-2026-63030
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-60137

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-60137
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score43.2vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction1.18 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
5.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-89
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.