SQL Injection Vulnerability in wp-post-author Plugin by WordPress
CVE-2026-108124

4.9MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-108124?

The wp-post-author plugin suffers from an SQL injection vulnerability that allows attackers to manipulate database queries. When untrusted input is improperly processed, it could lead to unauthorized access to sensitive data or execution of arbitrary SQL commands. This security flaw is present in all versions prior to 4.1.0, necessitating immediate updates to safeguard against potential exploitation.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.