AllCyberNews

CVE-2026-60137

WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

CVSS 5.9 medium · WordPress WordPress · published 2026-07-17

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Coverage 2 sources

  1. 2026-07-18 Help Net Security high Two new high severity WordPress vulnerabilities, patch immediately!

    WordPress 6.9 is vulnerable to two high-severity security issues, including a critical SQL injection issue.

  2. 2026-07-21 CISA Cybersecurity Advisories high CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation.

Mentioned with

CVE-2021-27137 CVE-2026-0770 CVE-2026-63030

Also covered