What is CVE-2026-12743?
This vulnerability affects the 'affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display' plugin for WordPress. It allows time-based SQL Injection via the 'orderby' parameter due to insufficient escaping and preparation. Users should update to the latest version or temporarily disable the plugin.
Azərbaycanca: Bu zəiflik WordPress üçün 'affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display' plagininə təsir edir. 'orderby' parametrində kifayət qədər qorunma olmaması səbəbindən zaman əsaslı SQL Injection hücumuna yol açır. İstifadəçilər plagini ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-12743?
This vulnerability affects the 'affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display' plugin.
What should users do to protect against CVE-2026-12743?
Users should update the plugin to the latest version or temporarily disable it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.