SQL Injection Vulnerability in WordPress Plugin Affects User Data Security
CVE-2026-40837

7.1HIGH

Key Information:

Vendor
CVE Published:
27 May 2026

What is CVE-2026-40837?

A low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings function. This vulnerability arises from improper neutralization of special elements in an SQL SELECT command, allowing attackers to potentially extract sensitive data, leading to a severe compromise of user confidentiality. It is crucial for users of the affected product to apply patches and take preventive measures to secure their installations.

Affected Version(s)

mbCONNECT24 0.0.0 <= 2.20.0

mbCONNECT24 2.20.0

mymbCONNECT24 0.0.0 <= 2.20.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.