SQL Injection Vulnerability in Ajax Search Pro Plugin from wpdreams
CVE-2026-96331

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-96331?

The Ajax Search Pro plugin by wpdreams is susceptible to SQL Injection due to improper handling of special elements within SQL commands. This vulnerability allows attackers to execute blind SQL injection attacks, potentially compromising the database. It affects multiple versions of the Ajax Search Pro plugin up to and including version 4.29.1, making it crucial for site administrators to update and secure their installations promptly.

Affected Version(s)

Ajax Search Pro 0 <= 4.29.1

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad | Patchstack Bug Bounty Program
.