SQL Injection Vulnerability in WordPress Plugin by Vendor X
CVE-2026-40848
7.1HIGH
What is CVE-2026-40848?
A low privileged remote attacker may exploit an unauthenticated SQL Injection vulnerability found in the tag view of a WordPress plugin by Vendor X. This vulnerability arises from improper handling of special elements in a SQL SELECT command, potentially leading to unauthorized access and loss of confidentiality for sensitive data.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
