Sceawere

Vulnerability Detail

CVE-2026-96346UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP ERP Author SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
3h ago
Vendor
weDevs
Product
WP ERP
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Author SQL Injection in WP ERP <= 1.17.9 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-09-30T13:17:29.570Z",
  "pubdate": "2026-09-30T13:17:29.570Z",
  "executiveSummary": "The WP ERP plugin for WordPress, in all versions up to and including 1.17.9, contains a critical SQL injection vulnerability.\nThis vulnerability allows authenticated users with the 'Author' role to execute arbitrary SQL commands against the underlying WordPress database.\nThe flaw stems from improper sanitization of user-supplied input before it is concatenated into SQL queries.\nAn attacker with low-privileged access can leverage this defect to bypass security controls, extract sensitive information including user credentials and configuration details, or potentially modify or delete data within the database.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the WordPress installation, as it permits unauthorized database manipulation via the application interface.",
  "technicalDetails": "The vulnerability resides in the backend processing logic of the WP ERP plugin where user-controlled parameters are passed directly to database query functions without sufficient escaping or the use of prepared statements.\nThe flaw manifests specifically in administrative or functional endpoints accessible to users holding the 'Author' role, which is typically insufficient to perform direct database operations.\nThe root cause is the failure to utilize the WordPress '$wpdb->prepare()' method or equivalent parameterized query mechanisms when handling inputs that influence the 'WHERE' or 'ORDER BY' clauses of SQL statements.\nExploitation flow typically begins when an authenticated 'Author' user triggers a specific request to the plugin's backend interface. By injecting malicious SQL syntax—such as 'UNION SELECT', 'SLEEP()', or boolean-based blind injection payloads—into vulnerable parameters, the attacker can manipulate the query logic.\nWhen the plugin processes this request, the database executes the injected commands within the context of the WordPress database user. This allows the attacker to retrieve data from arbitrary tables, circumvent authentication mechanisms, or gain unauthorized read/write access to the database.\nThe attack is characterized by its reliance on the lack of server-side input validation, which permits the alteration of the application's expected query structure. Because the application interacts directly with the database using the unsanitized input, the injected SQL commands are processed as legitimate parts of the query.\nPost-exploitation impact includes the full exposure of stored data, including administrative user hashes, session tokens, and plugin-specific configurations. Furthermore, if the database user permissions are overly permissive, an attacker might be able to utilize 'INTO OUTFILE' or 'LOAD_FILE' commands (if supported by the database configuration) to move toward further server compromise.\nGiven the vulnerability affects the plugin's internal request handling, the risk is persistent for any site where the plugin is active and 'Author' level accounts are exposed or compromised."
}
CVE-2026-96346: WP ERP Author SQL Injection (HIGH Severity, CVSS: 7.6) | Sceawere