What is CVE-2026-13119?
CVE-2026-13119 is an SQL Injection vulnerability in 'The Registrations For The Events Calendar' WordPress plugin up to version 3.2. Attackers can exploit JSON keys within the 'standard' parameter of the rtec_records_edit AJAX action to manipulate database queries. Immediately update the plugin to the patched version.
Azərbaycanca: CVE-2026-13119, 'The Registrations For The Events Calendar' WordPress plaqininin 3.2 və aşağı versiyalarını təsir edən SQL Injection zəifliyidir. Təcavüzkar rtec_records_edit AJAX əməliyyatında 'standard' parametrindəki JSON açarları vasitəsilə verilənlər bazasına müdaxilə edə bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-13119?
CVE-2026-13119 is an SQL Injection vulnerability affecting 'The Registrations For The Events Calendar' plugin up to version 3.2.
How can an attacker exploit CVE-2026-13119?
An attacker can exploit JSON keys within the 'standard' parameter of the rtec_records_edit AJAX action to manipulate database queries.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.