Sceawere

Vulnerability Detail

CVE-2026-89213UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Llavero.io SQL Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
8h ago
Vendor
Unknown
Product
Llavero.io
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-11T07:17:27.840Z",
  "pubdate": "2026-10-11T07:17:27.840Z",
  "executiveSummary": "The Llavero.io WordPress plugin, in versions through 0.1.4, contains a critical SQL injection vulnerability.\nThis vulnerability exists due to insufficient sanitization and escaping of user-supplied input before it is incorporated into database queries.\nUnauthenticated remote attackers can leverage this flaw to execute arbitrary SQL commands against the underlying database management system.\nSuccessful exploitation allows unauthorized access to sensitive information stored within the WordPress database, potentially leading to a complete compromise of the application's data integrity and confidentiality.\nThe vulnerability requires no prior authentication, significantly increasing its risk profile and accessibility to external threat actors.\nGiven the nature of SQL injection, this flaw poses a severe risk to the security posture of affected WordPress installations.",
  "technicalDetails": "The vulnerability resides in the way the Llavero.io plugin processes user-provided parameters before performing database interactions. Specifically, the input is passed directly into a SQL statement without undergoing appropriate sanitization or parameterized preparation. This failure to validate and neutralize malicious input allows an attacker to manipulate the structure of the intended SQL query.\nRoot Cause: The root cause is the improper handling of user-supplied input in a database query construction. By failing to use prepared statements or robust escaping functions (such as $wpdb->prepare()), the plugin allows the input parameter to break out of its intended data context and influence the SQL command syntax.\nAttack Flow: An attacker can intercept or craft an HTTP request containing a malicious payload injected into the vulnerable parameter. When the server processes this request, the application executes the manipulated SQL command. The attacker can then utilize techniques such as UNION-based SQL injection or blind SQL injection to extract data from the database, such as sensitive user records, configuration data, or administrative credentials.\nExploitation Method: Exploitation is straightforward and does not require authentication. An attacker can append SQL syntax to the affected parameter, effectively altering the query logic to return arbitrary data from the database tables. For example, by injecting 'UNION SELECT' statements, an attacker can append results from unauthorized tables to the output of the original query, or use 'SLEEP()' commands for time-based blind SQL extraction.\nImpact: The impact of this vulnerability is critical. Unauthorized entities can gain read access to the entire WordPress database, potentially exposing sensitive information such as user credentials, password hashes, site configuration, and private content. Furthermore, depending on the database configuration and permissions, some variants of SQL injection can lead to further escalation, such as writing files to the server or gaining remote code execution if the database user possesses sufficient privileges.\nComponent: The affected component is the internal database interface layer within the Llavero.io plugin that handles user-input parameters. Versions 0.1.4 and below are confirmed as vulnerable. The vulnerability is network-exposed, as the endpoint responsible for processing the input is accessible to any unauthenticated visitor to the website."
}
CVE-2026-89213: Llavero.io SQL Injection Vulnerability (HIGH Severity, CVSS: 8.6) | Sceawere