SQL Injection Vulnerability in wp-post-author by WordPress
CVE-2026-108125

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-108125?

The wp-post-author plugin for WordPress is vulnerable to SQL injection attacks, where improper handling of special elements within SQL commands can allow an attacker to manipulate database queries. This affects versions 4.0.0 and below, enabling exploitation that may lead to unauthorized data access or modification, posing significant risks to website integrity and user data safety.

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.