22 July 2026
Reference: CVE-2026-60137
1. What is being reported?
The issue is with WordPress versions before certain updates where a specific part of the system called 'author__not_in' is not properly checked. If a plugin or theme uses this part incorrectly, attackers can use it to run harmful database commands, potentially taking control of the website.
2. What this means in plain English
If your website runs WordPress and uses plugins or themes that interact with this part of WordPress, hackers could exploit this flaw to access sensitive data or take over your site. This could lead to website downtime, data loss, or your site being used to attack others.
3. Could this affect a small business?
Small businesses, charities, clubs, or any organisation using WordPress versions before 6.8.6, 6.9.5, or 7.0.2 could be at risk, especially if they use plugins or themes that pass data to the affected part of WordPress. If you do not use WordPress or keep it updated, you are likely not affected.
4. What to do now
- Check which version of WordPress your website is running.
- Update WordPress to the latest version as soon as possible, following the official update instructions.
- Ensure all plugins and themes are also updated to their latest versions.
- If you use a web hosting service or IT provider, ask them to confirm your site is protected against this vulnerability.
5. Ask your IT provider
Can you confirm that our WordPress site is updated to a version that fixes the CVE-2026-60137 vulnerability and that all plugins and themes are secure against this issue?
6. Bottom line
Keep your WordPress site and its components updated promptly to prevent hackers from exploiting this known security flaw.
Information based on CISA KEV, NVD, and multiple reputable security reports.