news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-60137

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.1 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Risk score
100.0
Known exploited
CISA KEV
Published
2026-07-17
Status
Published

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Weaknesses

CWE-89 SQL InjectionCWE-89

Coverage 7

ransomware

Don’t swing at everything

This week’s Threat Source newsletter highlights a new Rust-based remote access trojan (RAT), “msaRAT,” deployed by the Chaos ransomware group. The RAT leverages Chrome DevTools Protocol (CDP) to establish a covert comman…

Cisco Talos · Jul 23, 2026 High

Advisories and references