What is CVE-2026-18387?
The Groundhogg WordPress plugin up to version 4.5.14 is vulnerable to generic SQL Injection via the 'tag_query' parameter due to insufficient escaping and lack of proper preparation. This could allow unauthenticated attackers to compromise the database. Immediate update to the latest plugin version is strongly recommended.
Azərbaycanca: Groundhogg WordPress plugininin 4.5.14-ə qədər olan versiyalarında, 'tag_query' parametrində qeyri-kafi təmizləmə səbəbindən generic SQL Injection zəifliyi mövcuddur. Bu, autentifikasiya olunmamış hücumçulara verilənlər bazasına müdaxilə etməyə imkan verə bilər. Təcili olaraq plugini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Groundhogg WordPress plugin are affected by the CVE-2026-18387 SQL Injection vulnerability?
Versions up to 4.5.14 are affected.
Is authentication required to exploit CVE-2026-18387?
No, this vulnerability could allow unauthenticated attackers to compromise the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.