SQL Injection Vulnerability in Term Pages Plugin for WordPress
CVE-2026-16949

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 August 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-16949?

The Term Pages plugin for WordPress is susceptible to SQL injection due to inadequate sanitization and escaping of parameters before they are passed into SQL queries. This vulnerability enables unauthenticated attackers to exploit the flaw, potentially leading to unauthorized access and manipulation of database content. It is crucial for users of the plugin to update to version 2.0.0 or later to mitigate the risks associated with this security issue.

Affected Version(s)

Term Pages 0 < 2.0.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Ramos Maciel
WPScan
.