WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.8, < 6.8.6CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 6.9, < 6.9.5CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 7.0, < 7.0.2CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 6.8.0, < 6.8.6CPE match | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 6.9.0, < 6.9.5CPE match | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.