CVE-2026-94298
⚪ Do wiadomości
Wtyczka BuildKit do WordPressa umożliwia wstrzyknięcie SQL przez użytkowników z poziomem Contributor.
CVSS
6.2
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.2 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-10-02 06:16:43 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 18:00:34 UTC |