Summary
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query — affecting Wordpress.
Impact
Exploitability signals: listed in CISA KEV (known-exploited) · EPSS 78% · CVSS 5.9.
Affected systems
- Wordpress
Action
Review the vendor’s guidance and patch affected systems. Prioritise by exposure.
References
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137
This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:
Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.
Think a system in the community is affected or compromised?Report an incident