What is CVE-2026-16949?
This critical vulnerability in the Term Pages WordPress plugin before version 2.0.0 arises from a parameter not being properly sanitized and escaped before use in an SQL statement. It allows unauthenticated attackers to perform SQL injection attacks, compromising the database. Immediate update to version 2.0.0 or higher is recommended.
Azərbaycanca: Bu kritik boşluq Term Pages WordPress plaginin 2.0.0-dan əvvəlki versiyalarında "param" adlı parametrin düzgün təmizlənməməsi səbəbindən yaranır. Zəiflik autentifikasiya olunmamış hücumçulara SQL injection hücumları təşkil edərək verilənlər bazasına müdaxilə etməyə imkan verir. Dərhal plagini 2.0.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which version should the Term Pages plugin be updated to in order to be protected from the SQL injection risk?
The plugin should be immediately updated to version 2.0.0 or higher.
What does the CVE-2026-16949 vulnerability allow unauthenticated attackers to do?
This vulnerability allows unauthenticated attackers to perform SQL injection attacks, compromising the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.