CVE-2026-60137

EUVD-2026-45279
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 99.55%
Affected Products (NVD)
VendorProductVersion
wordpresswordpress
6.8 ≤
𝑥
< 6.8.6
wordpresswordpress
6.9 ≤
𝑥
< 6.9.5
wordpresswordpress
7.0 ≤
𝑥
< 7.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wordpress
bookworm
6.1.9+dfsg1-0+deb12u1
fixed
bookworm (security)
6.1.9+dfsg1-0+deb12u1
fixed
bullseye
5.7.11+dfsg1-0+deb11u1
fixed
bullseye (security)
5.7.14+dfsg1-0+deb11u1
fixed
forky
7.1+dfsg1-1
fixed
sid
7.1+dfsg1-1
fixed
trixie
vulnerable
trixie (security)
6.8.7+dfsg1-0+deb13u1
fixed