WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__notin parameter of WPQuery, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
{
"cpes": [
"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"
],
"severity": "Medium"
}