What is CVE-2026-16092?
This critical vulnerability is a second-order SQL Injection in the 'Improved Save Button' plugin for WordPress. Due to insufficient escaping on the 'meta_key' parameter via the 'Save and Duplicate' action, an authenticated user can interfere with the database. All versions up to and including 1.2.1 are affected; immediate update or temporary deactivation is recommended.
Azərbaycanca: Bu kritik boşluq WordPress üçün 'Improved Save Button' plaginində ikinci dərəcəli SQL Injection zəifliyidir. 'Save and Duplicate' funksiyası vasitəsilə 'meta_key' parametrinə daxil edilən məlumatların düzgün təmizlənməməsi səbəbindən autentifikasiyalı istifadəçi verilənlər bazasına müdaxilə edə bilər. Plaginin 1.2.1 və əvvəlki versiyaları təsirlənir, dərhal yenilənmə və ya müvəqqəti olaraq deaktiv edilmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-16092?
This vulnerability affects the 'Improved Save Button' plugin, versions 1.2.1 and earlier.
Is authentication required to exploit CVE-2026-16092?
Yes, an authenticated user is required to exploit this second-order SQL Injection vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.