PT-2026-60855 · WordPress · Wordpress
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress versions 6.8.0 through 6.8.5
WordPress versions 6.9.0 through 6.9.4
WordPress versions 7.0.0 through 7.0.1
Description
WordPress Core contains an SQL injection flaw that can be chained with other vulnerabilities to allow unauthenticated remote attackers to execute code on the server and take control of the website. The issue occurs because the
WP Query function does not properly sanitize the author not in parameter, which can be exploited when a plugin or theme passes untrusted input to it. This flaw potentially affects over 500 million sites worldwide.Recommendations
Update WordPress to version 6.8.6.
Update WordPress to version 6.9.5.
Update WordPress to version 7.0.2.
As a temporary mitigation, restrict access to the WordPress REST API.
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress