WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
| Vendor | Product | Versions |
|---|---|---|
| wordpress | wordpress | 6.8.0, 6.9.0, 7.0.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | wordpress | cert_advisory | 90% |
Loading…
Updated severity from MEDIUM to CRITICAL and CVSS from 5.9 to 9.8; added CWE-89 (SQL Injection); added MITRE ATT&CK techniques T1190, T1190.002, T1505.003, T1505.004; added new tags documenting observed attack techniques including webshell deployment, plugin upload abuse, LFI, and rogue admin account creation.
Updated CVSS score from 9.1 to 9.8 for the complete vulnerability chain as assessed by BSI; added IoC information about persistent webshells being deployed in active attacks.
Added WordPress 7.1.x before 7.1-beta2 to affected versions based on CERT-FR advisory, and added CERT-FR advisory reference tag.
Added WordPress 7.1.x versions (up to 7.1 beta2) to affected versions list, expanding the scope beyond the currently recorded 7.1.0.
Added WordPress 7.1.x versions (before 7.1 beta2) to affected versions list and added tags for CERT-FR advisory and public proof of concept availability.
Added technical details about CVE-2026-63030 REST API batch-route confusion vulnerability used in wp2shell RCE chain, expanded affected versions list, and added MITRE ATT&CK techniques.
Updated severity from MEDIUM to CRITICAL, CVSS score from 5.9 to 9.1, marked exploit as available and actively exploited, and added tags reflecting the chained vulnerability enabling unauthenticated code injection.
Updated severity to CRITICAL and CVSS score from 5.9 to 9.1; marked as actively exploited; added tag for chained exploit and code injection capability.
Updated severity to CRITICAL, added CVE ID (CVE-2026-60137), refined affected versions to include all point releases up to 6.8.5/6.9.4/7.0.1, and estimated CVSS at 9.0 for critical remote SQL injection vulnerability.
Initial creation