What is CVE-2026-12983?
This vulnerability affects the Dinatur WordPress plugin up to version 1.18, where user input is not sanitized before being used in SQL queries, leading to SQL injection by unauthenticated users. The same handler also lacks authorization checks, allowing unauthenticated database table truncation. Site administrators should deactivate the plugin and apply the security update immediately.
Azərbaycanca: Bu boşluq Dinatur WordPress plaginində (1.18 versiyası daxil olmaqla) aşkarlanıb. O, istifadəçi daxiletmələrinin SQL sorğularında təmizlənməməsi səbəbindən autentifikasiya olunmamış SQL injection hücumlarına, həmçinin eyni yerdə səlahiyyət yoxlaması olmadan verilənlər bazası cədvəlinin silinməsinə imkan verir. Sayt inzibatçıları plagini dərhal deaktiv edib təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which plugin is affected by CVE-2026-12983 and who can exploit it?
The vulnerability affects the Dinatur WordPress plugin up to version 1.18. It can be exploited by unauthenticated users for SQL injection attacks.
What immediate actions should site administrators take regarding CVE-2026-12983?
Site administrators should deactivate the plugin immediately and apply the security update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.