CVE-2026-60137
EUVD-2026-4527917.07.2026, 20:17
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wordpress | wordpress | 6.8 ≤ 𝑥 < 6.8.6 |
| wordpress | wordpress | 6.9 ≤ 𝑥 < 6.9.5 |
| wordpress | wordpress | 7.0 ≤ 𝑥 < 7.0.2 |
𝑥
= Vulnerable software versions
Debian Releases
Vulnerability Media Exposure