Sceawere
Vulnerability Detail
CVE-2026-81420UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tcard SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Tcard WP
- Attack Type
- CWE-89 SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Tcard WP WordPress plugin through 1.8.0 does not sanitise and escape a parameter before using it in a SQL statement in one of its unauthenticated AJAX actions, allowing unauthenticated users to perform SQL injection attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-11T07:17:24.593Z",
"pubdate": "2026-10-11T07:17:24.593Z",
"executiveSummary": "The Tcard WordPress plugin, up to and including version 1.8.0, contains an unauthenticated SQL injection (SQLi) vulnerability within one of its AJAX action handlers. This flaw stems from the failure to properly sanitize and escape user-supplied input before incorporating it into database queries.\nThe vulnerability allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying WordPress database. By injecting malicious SQL syntax through the vulnerable parameter, an attacker can bypass security controls to access, modify, or delete sensitive data stored within the database.\nThis represents a critical risk as it exposes the entire WordPress instance to potential data exfiltration, administrative account compromise, and unauthorized persistent access. Exploitation does not require prior authentication or elevated privileges, making it accessible to any actor capable of reaching the web server. Organizations relying on this plugin are at risk of a total site compromise, including the loss of user credentials and sensitive business information.",
"technicalDetails": "The vulnerability originates in the processing logic of an AJAX-enabled hook within the Tcard plugin. Specifically, the plugin fails to implement adequate input validation or parameterization when processing data transmitted via a GET or POST request intended for an unauthenticated AJAX endpoint.\nThe root cause is identified as the direct concatenation of unvalidated user input into a SQL query string. Because the application logic does not utilize WordPress-native database abstraction functions like $wpdb->prepare() or perform strict type-casting and sanitization (e.g., using sanitize_text_field() or intval()), the database engine interprets the malicious input as part of the SQL command rather than as data.\nThe attack flow proceeds as follows: First, the attacker identifies the vulnerable AJAX action and the specific parameter that is being passed to the SQL query. Second, the attacker crafts a payload utilizing SQL union-based, error-based, or blind injection techniques. This payload typically includes SQL control characters (such as single quotes, comments like '--' or '#', and UNION keywords) to manipulate the original query structure.\nWhen the web server processes the request, the application passes the malicious payload to the database layer without sufficient sanitization. The database executes the injected commands, which may result in the disclosure of administrative password hashes, database schema mapping, or sensitive configuration details. In certain database configurations, this may also facilitate stacked queries, allowing the attacker to execute Data Manipulation Language (DML) operations, such as 'INSERT' or 'UPDATE', potentially leading to the creation of unauthorized administrative accounts.\nThe impact is comprehensive: an attacker can gain full read/write access to the database. Given that the plugin operates within the WordPress ecosystem, successful exploitation often leads to remote code execution (RCE) scenarios, as attackers can modify the wp_users table or inject malicious logic directly into the options table. Because this endpoint is exposed for unauthenticated access, the attack surface is exposed to the public internet, requiring no special network positioning other than visibility to the WordPress site's AJAX interface."
}