SQL Injection Vulnerability in TaxoPress by Steve Burge
CVE-2026-42646
7.6HIGH
What is CVE-2026-42646?
An SQL Injection vulnerability exists in the TaxoPress plugin developed by Steve Burge, allowing attackers to perform Blind SQL Injection attacks. This flaw affects TaxoPress versions up to and including 3.44.0. Exploiting this vulnerability may enable unauthorized access to sensitive data, compromising the integrity of the application and exposing databases to manipulation.
Affected Version(s)
TaxoPress 0 <= 3.44.0