PT-2026-104092 · Undefined · Undefined
CVSS v3.1
6.2
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N |
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined