Description
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected products
- WordPress / WordPress6.8.0 – 6.8.6
- WordPress / WordPress6.9.0 – 6.9.5
- WordPress / WordPress7.0.0 – 7.0.2
- WordPress / WordPress6.8 – 6.8.6
News coverage
- Critical wp2shell WordPress flaws exploited to install webshellsBleepingComputer · 7/21/2026
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningThe Hacker News · 7/21/2026
- 'WP2Shell' Opens Millions of WordPress Sites to Remote TakeoverDark Reading · 7/20/2026
Updated 5m ago · 8 sources