Response playbooks, investigation guides, and Atomic Red Team tests are Pro-only. Upgrade to unlock the full detection package for CVE-2026-60137.

Upgrade to Pro
CVE-2026-60137 Google Chronicle · YARA-L

Detect WordPress Core SQL Injection Exploitation (CVE-2026-60137) in Google Chronicle

Detects exploitation attempts and successful exploitation of CVE-2026-60137, a SQL injection vulnerability (CWE-89) in WordPress Core affecting unauthenticated or authenticated request handling. This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and is actively being exploited in the wild. Exploitation typically manifests as anomalous SQL syntax in HTTP request parameters targeting WordPress endpoints (wp-admin, wp-json REST API, xmlrpc.php, plugin/theme AJAX handlers), followed by unusual database error responses, data exfiltration patterns, or subsequent webshell/backdoor deployment. WordPress 7.0.2 remediates this issue; unpatched sites remain at critical risk per CISA BOD 26-04 prioritization guidance.

MITRE ATT&CK

Tactic
Initial Access Execution Credential Access

YARA-L Detection Query

Google Chronicle (YARA-L)
yaral
rule wordpress_core_sqli_cve_2026_60137 {
  meta:
    description = "Detects SQLi patterns targeting WordPress core endpoints (CVE-2026-60137)"
    severity = "CRITICAL"
    cve = "CVE-2026-60137"
  events:
    $e.metadata.event_type = "NETWORK_HTTP"
    $e.target.url = /(\/wp-admin|\/wp-json|\/xmlrpc\.php|\/wp-content\/plugins)/ nocase
    $e.network.http.method != ""
    $e.target.url = /(UNION(\s|%20)+SELECT|1(\s|%20)*=(\s|%20)*1|information_schema|SLEEP\(|benchmark\(|0x2727)/ nocase
  match:
    $e.principal.ip over 5m
  condition:
    $e
}
critical severity medium confidence

Chronicle YARA-L rule matching SQL injection syntax in HTTP requests to WordPress core paths, aligned with active KEV exploitation of CVE-2026-60137.

Data Sources

Network HTTP EventsWeb Proxy Logs

Required Tables

NETWORK_HTTP

False Positives & Tuning

  • Legitimate security research or authorized penetration testing traffic
  • Third-party monitoring integrations that mirror raw query strings into logs
  • Rare but valid application query parameters coincidentally matching regex tokens

Other platforms for CVE-2026-60137


Testing Methodology

Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Simulate SQLi Probe Against wp-json Endpoint

    Expected signal: Web server access log entry with URI query containing 'UNION SELECT' and 'wp_users' targeting /wp-json/wp/v2/posts.

  2. Test 2Simulate SQLi Probe Against xmlrpc.php

    Expected signal: Web access log entry showing xmlrpc.php request with "' OR '1'='1" in the query string.

  3. Test 3Simulate Time-Based Blind SQLi Probe

    Expected signal: Web access log entry for admin-ajax.php containing 'SLEEP(5)' with an observable elevated response time in the log or APM data.

  4. Test 4Simulate Successful SQLi Followed by Server Error

    Expected signal: Two sequential access log entries from the same source IP within a 5-minute window: one containing 'information_schema' and one resulting in an HTTP 500 response.

Unlock playbooks & atomic tests with Pro

Get the full detection package for CVE-2026-60137 — response playbook and atomic red team tests, plus investigation guidance and hunting queries.

df00tech Pro — £29/user/month

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections