Unauthenticated SQL Injection in Everest Backup Plugin by Everest
CVE-2026-66472
9.3CRITICAL
What is CVE-2026-66472?
The Everest Backup plugin for WordPress is susceptible to an unauthenticated SQL Injection vulnerability, allowing attackers to manipulate database queries without prior authentication. This may result in unauthorized data exposure or modification. Users of Everest Backup versions 2.3.12 and below should apply patches immediately to mitigate potential exploits.
Affected Version(s)
Everest Backup <= 2.3.12