CVE
CVE-2026-60137
- First Reported
- Oct 1, 2026
- Latest Reported
- Oct 1, 2026
Reported Context (1)
- CVE-2026-60137 describes insufficient sanitization of the author__not_in parameter in WP_Query, enabling SQL injection when untrusted input reaches that parameter. TIKTOUK Toolkit Collects WordPress, Email, and Cloud Credentials
CVE (1)
MITRE ATT&CK (4)
Products (4)
Tools (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.