Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Urgent WordPress Security Flaw Could Let Hackers Access Your Website

A security weakness in WordPress core software has been found that could allow hackers to exploit certain website setups to run harmful commands. This vulnerability is actively being exploited, making it important for organisations using WordPress to act quickly to protect their sites.

22 July 2026

Reference: CVE-2026-60137

1. What is being reported?

The issue is with WordPress versions before certain updates where a specific part of the system called 'author__not_in' is not properly checked. If a plugin or theme uses this part incorrectly, attackers can use it to run harmful database commands, potentially taking control of the website.

2. What this means in plain English

If your website runs WordPress and uses plugins or themes that interact with this part of WordPress, hackers could exploit this flaw to access sensitive data or take over your site. This could lead to website downtime, data loss, or your site being used to attack others.

3. Could this affect a small business?

Small businesses, charities, clubs, or any organisation using WordPress versions before 6.8.6, 6.9.5, or 7.0.2 could be at risk, especially if they use plugins or themes that pass data to the affected part of WordPress. If you do not use WordPress or keep it updated, you are likely not affected.

4. What to do now

  • Check which version of WordPress your website is running.
  • Update WordPress to the latest version as soon as possible, following the official update instructions.
  • Ensure all plugins and themes are also updated to their latest versions.
  • If you use a web hosting service or IT provider, ask them to confirm your site is protected against this vulnerability.

5. Ask your IT provider

Can you confirm that our WordPress site is updated to a version that fixes the CVE-2026-60137 vulnerability and that all plugins and themes are secure against this issue?

6. Bottom line

Keep your WordPress site and its components updated promptly to prevent hackers from exploiting this known security flaw.

Information based on CISA KEV, NVD, and multiple reputable security reports.

Back to Vulnerability Briefs