What is CVE-2026-14238?
The vitepos WordPress plugin before version 3.6.0 fails to sanitize an identifier from a REST request body before using it in a database query within a report endpoint, allowing high-privilege users to perform SQL injection attacks.
Azərbaycanca: Vitepos WordPress plaqini 3.6.0-dan əvvəlki versiyalarda REST sorğusundan alınan identifikatoru sanitizasiya etmir, bu da administrator səviyyəli istifadəçilərə SQL injection hücumu həyata keçirməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which user roles are affected by the SQL injection vulnerability in the Vitepos plugin?
This vulnerability affects only administrator-level users, as the REST request requires high privileges.
What version should be upgraded to in order to protect against the SQL injection vulnerability in the Vitepos plugin?
To protect your site, it is recommended to upgrade the Vitepos WordPress plugin to at least version 3.6.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.