Sceawere

Vulnerability Detail

CVE-2026-94298UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

BuildKit SQL Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.2
Creation Date
17h ago
Vendor
Unknown
Product
BuildKit
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.2",
  "pubDate": "2026-10-02T06:16:43.387Z",
  "pubdate": "2026-10-02T06:16:43.387Z",
  "executiveSummary": "The BuildKit WordPress plugin before version 1.0.29 contains a critical SQL injection vulnerability originating from improper input handling. The vulnerability resides in the way user-supplied data from contributors is processed, stored, and subsequently retrieved for use in database queries.\nThe flaw allows an authenticated user with contributor-level privileges to inject arbitrary SQL commands. When the malicious content is published and rendered on the front end, these commands are executed against the site's database during the processing of the page or post.\nThe impact of this vulnerability is severe, potentially leading to unauthorized data exposure, database modification, or full administrative takeover depending on the database configuration and permissions. Exploitation requires authenticated access to a contributor account, but the trigger for the execution occurs automatically upon viewing the compromised content, even by unauthenticated visitors. This represents a significant security risk for installations running affected versions of BuildKit.",
  "technicalDetails": "The vulnerability is classified as an SQL injection arising from the failure to apply robust input sanitization and output escaping protocols to data submitted by contributor-level users. Within the BuildKit plugin, user input is accepted and persisted to the WordPress database without adequate validation or parameterization.\nThe root cause is the improper handling of metadata or post content that is subsequently passed into SQL queries without the use of WordPress’s database abstraction layer mechanisms, such as $wpdb->prepare(). By failing to sanitize the input during the storage phase, the application allows malicious SQL syntax to reside in the database tables.\nThe attack flow begins when a contributor-level user crafts a payload containing malicious SQL fragments. These fragments are submitted through the plugin's interface. Because the application logic does not neutralize these inputs, the payload is committed directly to the database. The vulnerability is triggered during the retrieval process; when an unauthenticated visitor accesses a page where the malicious content is rendered, the plugin executes the stored query. Because the query execution involves the previously injected malicious SQL, the database engine processes the concatenated commands.\nThis execution happens in the context of the database user configured for the WordPress installation. Depending on the complexity of the query, an attacker could extract sensitive information (e.g., WordPress user hashes, session tokens, or private configuration data) by using UNION-based SQL injection techniques, or perform blind data exfiltration using time-based or boolean-based inference.\nSince the payload execution is decoupled from the initial injection—triggering only upon the display of the content—the vulnerability facilitates persistent malicious behavior. An attacker does not need to maintain an active session for the SQL injection to execute; it will trigger whenever the compromised post or page is accessed by any site visitor, including administrative accounts. This characteristic increases the likelihood of privilege escalation or mass data exfiltration if an administrator inadvertently views the injected content.\nAffected versions include all BuildKit plugin releases prior to 1.0.29. The vulnerability is characterized by a failure to maintain a strict separation between data and executable code in database interactions, violating fundamental secure coding principles within the WordPress development ecosystem."
}
CVE-2026-94298: BuildKit SQL Injection Vulnerability (MEDIUM Severity, CVSS: 6.2) | Sceawere