SQL Injection Vulnerability in Saleswonder LLC's WebinarIgnition
CVE-2026-40797

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 May 2026

What is CVE-2026-40797?

The WebinarIgnition plugin by Saleswonder LLC is susceptible to an SQL Injection vulnerability, which allows for blind SQL injection attacks. This flaw can potentially enable unauthorized users to manipulate database queries, accessing sensitive data or compromising the integrity of the database. All versions earlier than 4.08.253 are affected, requiring urgent attention to mitigate potential security threats.

Affected Version(s)

WebinarIgnition <= 4.08.253

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dahmani Toumi (pega_SUS) | Patchstack Bug Bounty Program
.