Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical0
High1
Medium0
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-08-19

CVE-2026-12983 - Allowing Any Unauthenticated Visitor To Wipe The Dinatur Plugin

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.

PLUGIN Allowing Any Unauthenticated Visitor To Wipe The Dinatur

CVE-2026-12983

HIGH CVSS 8.6 2026-08-19
Scroll to top