SQL Injection Vulnerability in Ultimeter Plugin by WordPress
CVE-2026-95593

7.6HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-95593?

The Ultimeter plugin for WordPress has been found to be susceptible to SQL Injection vulnerabilities in versions up to 3.0.8. This security flaw allows attackers to manipulate SQL queries by exploiting improper input validation within the editor feature. As a result, unauthorized individuals may gain access to sensitive data and execute harmful commands on the database, posing significant security risks to WordPress sites utilizing this plugin. Website administrators are urged to update to the latest version and apply best security practices to mitigate potential threats.

Affected Version(s)

Ultimeter <= 3.0.8

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.