WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
WordPress Core fails to sanitize the `author__not_in` parameter of `WP_Query` before incorporating it into a database query. When a plugin or theme passes attacker-controlled input to this parameter without prior validation, the unsanitized value is interpolated directly into SQL, producing a CWE-89 injection condition. WordPress Core itself does not expose this parameter directly to unauthenticated users; a plugin or theme acting as the trust-boundary crossing point is required for the flaw to be reachable.
An attacker submits crafted input to a WordPress endpoint exposed by a vulnerable plugin or theme that passes the value to `WP_Query`'s `author__not_in` parameter. The resulting SQL injection can yield database contents, including credential hashes and user data. When chained with CVE-2026-63030, which affects WordPress 6.9.x and 7.0.x but not 6.8.x, an unauthenticated attacker can achieve remote code execution. Sites running only 6.8.x face the SQL injection risk but are not affected by the chained RCE path.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If WordPress Core runs inside your authorization boundary, yes. CVE-2026-60137 appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 4, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding that your assessor and sponsoring agency will raise. You address it by remediating the vulnerability or formally documenting a mitigation before that deadline arrives.
Remediating WordPress Core is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage on your own.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-60137. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team the lead time to act before a finding becomes a formal problem.
Knox runs a FedRAMP-as-a-Service platform. You deploy your application inside a pre-authorized cloud boundary that spans AWS, Azure, and Google Cloud. Your application inherits 60–80% of the required security controls on day one. Knox's automated continuous monitoring handles control mapping, vulnerability detection, and documentation. You do not need an agency sponsor to begin. The result is FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting to learn more.
If you miss the August 4, 2026 deadline, CVE-2026-60137 becomes a Plan of Action and Milestones (POA&M) item. When your POA&M list grows, a routine continuous-monitoring review turns into a difficult conversation with your sponsoring agency. If you meet the deadline, your authorization stays clean and your agency relationship stays intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









