CVE-2026-60137
Known exploited · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 78% (100th percentile).
CISA federal remediation date Aug 4
Vulnerabilities · 42 days ago
Unpatched Internet-facing WordPress Core sites are already in automated attack traffic, so this is no longer a theoretical takeover path. The useful warning is not the bug itself. It is that once a site was reachable during the window, patching alone may not remove the attacker state left behind.
FortiGuard says it blocked 4,649 exploitation attempts in the past 24 hours and saw 88,452 detections over seven days. The chain combines CVE-2026-63030, a REST API batch route confusion issue, with CVE-2026-60137, a WP_Query SQL injection, and the fixed versions are 6.8.6, 6.9.5, and 7.0.2 or later.
That scale points to automated scanning and likely persistent compromise on exposed sites, not a niche proof of concept. For operators of public WordPress estates, the real risk is attacker presence that survives the patch as web shells or unauthorized admin accounts.
Known exploited · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 78% (100th percentile).
CISA federal remediation date Aug 4
Known exploited · CISA KEV
CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…
CISA federal remediation date Jul 24 · date passed
3 sources covering this story
Múltiples vulnerabilidades en WordPress Core
WordPress ha publicado dos vulnerabilidades, una de severidad crítica y otra de severidad alta, que af
WP2Shell RCE | Outbreak Alert | FortiGuard Labs
FortiGuard Labs continues to detect exploitation attempts targeting the WP2Shell attack chain (CVE-2026-63030 and CVE-2026-60137), a critical unaut...
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Attack?FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code executi...
Part of the PlainSec briefing for 2026-08-09