SQL Injection Vulnerability in Milan Petrovic GD Rating System
CVE-2026-57771

8.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 July 2026

What is CVE-2026-57771?

An improper neutralization of special elements used in SQL commands is present in the GD Rating System plugin by Milan Petrovic. This flaw can lead to Blind SQL Injection attacks, potentially compromising the database through the manipulation of SQL queries. The affected versions include all versions up to 3.7, allowing malicious actors to execute arbitrary SQL commands and retrieve sensitive information, highlighting the need for immediate updates and security patches.

Affected Version(s)

GD Rating System 0 <= 3.7

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VanTastic | Patchstack Bug Bounty Program
.