SQL Injection vulnerabilities in WordPress plugins and themes
SQL injection happens when input from a request is placed into a database query without being separated from the query itself. An attacker who controls that input controls the query, which in practice means reading the whole database — every user row, every password hash, every stored order. It is the highest-consequence flaw class on this list because the database is where everything worth stealing lives.
What an attacker can do: read, alter or delete anything in the site database, including user accounts and password hashes CWE-89
- Wpforo - SQL Injection (CVE-2026-5097) HIGH
- Suggestion Engine for WooCommerce - SQL Injection (CVE-2026-81277) HIGH
- Beautiful Taxonomy Filters - SQL Injection (CVE-2026-78288) CRITICAL
- Like Button Rating - SQL Injection (CVE-2026-78285) HIGH
- Epayco - SQL Injection (CVE-2026-78260) CRITICAL
- Custom Post Types - SQL Injection (CVE-2026-32564) HIGH
- Kadence Shop Kit - SQL Injection (CVE-2026-32550) HIGH
- Visitor Traffic Real Time Statistics Pro - SQL Injection (CVE-2026-32479) CRITICAL
- Woocommerce Lottery - SQL Injection (CVE-2026-18884) HIGH
- Registrationmagic - SQL Injection (CVE-2026-77790) UNKNOWN
- Tutor Lms - SQL Injection (CVE-2026-19094) MEDIUM
- And Crm Solution - SQL Injection (CVE-2026-78468) MEDIUM
- Media Sweep - SQL Injection (CVE-2026-77824) MEDIUM
- All In One Wp Migration - SQL Injection (CVE-2026-19949) HIGH
- Readabler - SQL Injection (CVE-2026-78576) HIGH
- Total Donations - SQL Injection (CVE-2026-78568) CRITICAL
- Wp Project Manager Pro - SQL Injection (CVE-2026-78470) MEDIUM
- Events Manager - SQL Injection (CVE-2026-15023) MEDIUM
- Boost - SQL Injection (CVE-2026-32555) CRITICAL
- WooBeWoo Product Filter Pro - SQL Injection (CVE-2026-32554) CRITICAL
- FluentCRM Pro - SQL Injection (CVE-2026-78270) HIGH
- Woo Essential - SQL Injection (CVE-2026-32551) CRITICAL
- WP Project Manager Pro - SQL Injection (CVE-2026-32478) HIGH
- ProLancer Element - SQL Injection (CVE-2026-32471) HIGH
- Media Library Assistant - SQL Injection (CVE-2026-16959) MEDIUM
- Link Whisper Free - SQL Injection (CVE-2026-14601) MEDIUM
- CVE-2026-74011 HIGH
- eShipper Commerce - SQL Injection (CVE-2026-74013) HIGH
- WP w3all phpBB - SQL Injection (CVE-2026-73998) HIGH
- BookingPress Appointment Booking Pro - SQL Injection (CVE-2026-68566) CRITICAL