What is CVE-2026-16572?
CVE-2026-16572 is a critical SQL injection vulnerability in the LogMyTrip WordPress plugin. The plugin (versions up to 1.9) fails to sanitize and escape a value taken from a cookie before using it in an SQL query, allowing unauthenticated attackers to perform SQL injection attacks on any page rendering the plugin's shortcodes. Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-16572, LogMyTrip WordPress plaginində aşkarlanmış kritik bir SQL injection zəifliyidir. Plagin (1.9-a qədər versiyalar) cookie-dən alınan dəyəri SQL sorğusunda istifadə etməzdən əvvəl sanitizə etmir, bu da autentifikasiya olunmamış hücumçulara plagının shortcode-larını göstərən istənilən səhifədə SQL injection hücumu həyata keçirməyə imkan verir. Plaginin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
How does the CVE-2026-16572 vulnerability affect LogMyTrip plugin users?
This critical SQL injection vulnerability allows unauthenticated attackers to perform SQL injection attacks on any page rendering the plugin's shortcodes.
What should I do to protect against CVE-2026-16572?
You should immediately update the LogMyTrip plugin to the latest version, as versions up to 1.9 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.