What is CVE-2026-15018?
This vulnerability allows time-based SQL Injection in the 'Database Collation Fix' plugin for WordPress via the 'force-collation-algorithm' parameter. It affects all versions up to 1.2.10 and users should immediately update or deactivate the plugin to mitigate the risk.
Azərbaycanca: Bu boşluq WordPress-in 'Database Collation Fix' plaginində 'force-collation-algorithm' parametri vasitəsilə time-based SQL Injection hücumuna imkan verir. Plaginin 1.2.10 və daha əvvəlki versiyalarını təsir edir; istifadəçilər dərhal plaqini yeniləməli və ya deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-15018?
This vulnerability affects the 'Database Collation Fix' plugin versions 1.2.10 and earlier.
How is CVE-2026-15018 exploited?
The vulnerability allows a time-based SQL Injection attack via the 'force-collation-algorithm' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.