SQL Injection Vulnerability in Saleswonder LLC's WebinarIgnition
CVE-2026-40797
9.3CRITICAL
What is CVE-2026-40797?
The WebinarIgnition plugin by Saleswonder LLC is susceptible to an SQL Injection vulnerability, which allows for blind SQL injection attacks. This flaw can potentially enable unauthorized users to manipulate database queries, accessing sensitive data or compromising the integrity of the database. All versions earlier than 4.08.253 are affected, requiring urgent attention to mitigate potential security threats.
Affected Version(s)
WebinarIgnition <= 4.08.253
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dahmani Toumi (pega_SUS) | Patchstack Bug Bounty Program