CVE-2026-94298

⚪ Do wiadomości

Wtyczka BuildKit do WordPressa umożliwia wstrzyknięcie SQL przez użytkowników z poziomem Contributor.

CVSS
6.2
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.2
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-10-02 06:16:43 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:00:34 UTC
Referencje