SQL Injection Vulnerability in Cornerstone Plugin by WordPress
CVE-2026-54185

8.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2026-54185?

A security flaw exists in the Cornerstone plugin for WordPress, where improper validation and sanitization of user input can lead to SQL injection vulnerabilities. This issue affects all versions prior to 7.8.8, allowing attackers to manipulate SQL queries by injecting malicious code through user-supplied data. Such vulnerabilities can result in unauthorized access to sensitive data, database alteration, or even complete site takeover if exploited. Users are strongly advised to update to the latest version of the plugin to mitigate this risk.

Affected Version(s)

Cornerstone < 7.8.8

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.