SQL Injection Vulnerability in Database Collation Fix Plugin for WordPress
CVE-2026-15018

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2026

What is CVE-2026-15018?

The Database Collation Fix plugin for WordPress suffers from a vulnerability that permits time-based SQL injection attacks via the 'force-collation-algorithm' parameter. This issue stems from inadequate escaping of user-supplied input and insufficiently prepared SQL queries. Unauthenticated attackers can exploit this flaw to inject arbitrary SQL statements into existing queries, which could potentially lead to unauthorized access to sensitive data stored in the database. Notably, exploitation is contingent on the presence of a trigger.txt file in the plugin's directory, a scenario often created by certain DesktopServer integration actions such as site creation or migration.

Affected Version(s)

Database Collation Fix 0 <= 1.2.10

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan
.