WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
WordPress Core fails to sanitize the `author__not_in` parameter of `WP_Query` before incorporating its value into a database query. When a plugin or theme accepts external input and passes it to this parameter without independent validation, the unsanitised value is interpolated directly into SQL, producing a CWE-89 injection condition. The flaw is described as facilitated because WordPress Core is the vulnerable component, but the attack path requires an intermediary plugin or theme to relay attacker-controlled data to the parameter. Affected versions span the 6.8.x, 6.9.x, and 7.0.x release lines.
An attacker submits crafted input through whatever HTTP interface a vulnerable plugin or theme exposes, such as a query parameter, form field, or REST API argument, that the plugin or theme then passes to `WP_Query` via `author__not_in`. The injected SQL payload can read or write database contents, including credential hashes, user data, and site configuration. When chained with CVE-2026-63030, an unauthenticated attacker can escalate from SQL injection to remote code execution on default WordPress installations. Exploitability depends on a susceptible plugin or theme being present and passing external input to the affected parameter.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If WordPress Core runs inside your authorization boundary, yes. CVE-2026-60137 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of August 4, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.
Knox doesn't patch your software for you — remediating WordPress Core is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.
Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.
Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.
It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.
Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.
FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.
Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.
Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.







_Horizontal_RGB.png)








