MediumTLP:CLEARGARNET-CSIRT-2026-001

WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query

Medium severity. Plan remediation soon.

Summary

WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query — affecting Wordpress.

Impact

Exploitability signals: listed in CISA KEV (known-exploited) · EPSS 78% · CVSS 5.9.

Affected systems

  • Wordpress

Action

Review the vendor’s guidance and patch affected systems. Prioritise by exposure.

References

https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137

§ Verify this advisory✓ PGP-signed

This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:

$ curl -O https://csirt.garnet.edu.gh/advisories/2026-001-wordpress-702-facilitated-sql-injection-via-author-not-in-in.md
$ curl -O https://csirt.garnet.edu.gh/advisories/2026-001-wordpress-702-facilitated-sql-injection-via-author-not-in-in.md.asc
$ gpg --import garnet-csirt.asc
$ gpg --verify 2026-001-wordpress-702-facilitated-sql-injection-via-author-not-in-in.md.asc 2026-001-wordpress-702-facilitated-sql-injection-via-author-not-in-in.md

Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.


Think a system in the community is affected or compromised?Report an incident