SQL Injection Vulnerability in Askeet Plugin for WordPress
CVE-2026-5651
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-5651?
The Askeet plugin for WordPress is susceptible to SQL injection attacks through the 'sql_query' parameter in various AJAX actions, including askeet_execute_sql_query and askeet_export_all_results. This vulnerability arises from the bypassing of the askeet_is_safe_query() filter, which fails to properly mitigate risks associated with MySQL conditional comments. As a result, authenticated users with Administrator-level access can exploit this weakness to inject malicious SQL queries, potentially leading to unauthorized access and extraction of sensitive data from the database.
Affected Version(s)
Askeet — Talk to Your WooCommerce Data 0 <= 3.0