What is CVE-2026-15304?
A SQL injection vulnerability has been identified in the Plugin Organizer plugin for WordPress (up to version 10.2.4) via the 'PO_plugin_path' parameter. It arises from insufficient escaping of user-supplied input in the perform_plugin_search() function. Websites using this plugin should update immediately or temporarily disable it.
Azərbaycanca: WordPress üçün Plugin Organizer plaginində (versiya 10.2.4-ə qədər) 'PO_plugin_path' parametri vasitəsilə SQL injection zəifliyi aşkar edilib. Bu boşluq, istifadəçi tərəfindən ötürülən parametrin perform_plugin_search() funksiyasında kifayət qədər qorunmaması nəticəsində yaranır. Plagindən istifadə edən saytlar dərhal ən son versiyaya yenilənməli və ya müvəqqəti olaraq deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin and function are affected by CVE-2026-15304?
The vulnerability affects the PO_plugin_path parameter in the perform_plugin_search() function of the Plugin Organizer plugin.
What is the latest version to protect against this SQL injection vulnerability?
The context mentions that versions up to 10.2.4 are vulnerable, but the exact latest secure version is not specified.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.