---
title: "WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query"
summary: "WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query"
severity: medium
status: active
advisoryId: "GARNET-CSIRT-2026-001"
published: 2026-08-10
affected:
  - "wordpress"
cves:
  - "CVE-2026-60137"
tags:
  - "wordpress"
  - "kev"
tlp: CLEAR
references:
  - title: "TIDE · cna"
    url: "https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf"
  - title: "TIDE · cna"
    url: "https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"
  - title: "TIDE · adp"
    url: "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137"
draft: false
---

## Summary

WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query — affecting Wordpress.

## Impact

Exploitability signals: listed in CISA KEV (known-exploited) · EPSS 78% · CVSS 5.9.

## Affected systems

- Wordpress

## Action

Review the vendor's guidance and patch affected systems. Prioritise by exposure.

## References
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137
