What is CVE-2026-16539?
This is an SQL injection vulnerability in the sm page duplicator WordPress plugin up to version 1.0.0. The plugin does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL injection attacks. It is recommended to update the plugin to the latest version.
Azərbaycanca: Bu, sm page duplicator WordPress plaginində (1.0.0 versiyasına qədər) aşkarlanan bir SQL injection zəifliyidir. Plagin, səhifə dublikatı zamanı saxlanılan bir dəyəri SQL sorğusunda istifadə etməmişdən əvvəl təmizləmir, bu da Editor və daha yüksək rollu istifadəçilərə SQL injection hücumu həyata keçirməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What user role level does an attacker need to exploit CVE-2026-16539?
To exploit this vulnerability, an attacker must have at least the Editor role or a higher-level user role.
What is the primary recommendation to mitigate CVE-2026-16539?
It is recommended to update the sm page duplicator plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.