Unauthenticated SQL Injection in wpDataTables Plugin by WordPress
CVE-2026-49080
9.3CRITICAL
What is CVE-2026-49080?
An SQL Injection vulnerability exists in the wpDataTables plugin for WordPress versions up to 7.3.6. This flaw allows attackers to execute arbitrary SQL queries through unauthenticated requests, potentially leading to unauthorized access to sensitive database information. It's crucial for site administrators to update to the latest version to mitigate associated risks and protect user data.
Affected Version(s)
wpDataTables <= 7.3.6