What is CVE-2026-12877?
The WordPress plugin "Project Management, Bug and Issue Tracking Plugin" prior to version 5.1.0 fails to sanitize and escape user input before using it in a SQL query, allowing unauthenticated SQL injection attacks. This is exploitable in the Project Management section, and updating the plugin to the latest version is required.
Azərbaycanca: "The Project Management, Bug and Issue Tracking Plugin" adlı WordPress plagini (5.1.0 versiyasından əvvəl) istifadəçi daxiletməsini SQL sorğusunda istifadə etməzdən əvvəl təmizləmədiyi (sanitize) üçün autentifikasiya olunmamış SQL injection hücumları mümkündür. Bu zəiflik xüsusilə Proyekt İdarəetmə bölməsində istismar edilə bilər; plagin ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-12877 and which versions are vulnerable?
This vulnerability affects the 'Project Management, Bug and Issue Tracking Plugin'. All versions prior to 5.1.0 are vulnerable.
Does exploiting CVE-2026-12877 require authentication?
No, this vulnerability allows for unauthenticated SQL injection attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.