What is CVE-2026-15351?
This vulnerability exists in the WC Vendors plugin for WordPress. It allows generic SQL Injection via the 'status' parameter due to insufficient escaping of user-supplied input. All users should immediately update the plugin to the latest version.
Azərbaycanca: Bu zəiflik WordPress üçün WC Vendors pluginində aşkarlanıb. 'status' parametri vasitəsilə SQL injection hücumuna imkan verir, çünki istifadəçi tərəfindən təqdim edilən məlumatlar yetərincə təmizlənmir. Bütün istifadəçilər pluqini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which plugin was CVE-2026-15351 discovered?
This vulnerability exists in the WC Vendors plugin for WordPress.
What type of attack does CVE-2026-15351 allow and what is its cause?
The vulnerability allows a generic SQL Injection attack via the 'status' parameter due to insufficient escaping of user-supplied input.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.