What is CVE-2026-66668?
CVE-2026-66668 is a Subscriber-level SQL Injection vulnerability in the Community by PeepSo plugin versions <= 9.0.5.2. This flaw allows authenticated users with subscriber role to execute arbitrary SQL queries against the database. To mitigate, users are advised to immediately update PeepSo to the latest version.
Azərbaycanca: CVE-2026-66668, PeepSo plaginin 9.0.5.2 və daha əvvəlki versiyalarında abunəçi səviyyəsində SQL Injection zəifliyidir. Bu boşluq autentifikasiya olunmuş abunəçi roluna malik istifadəçilərə verilənlər bazasına qarşı ixtiyari SQL sorğuları icra etməyə imkan verir. Zəiflikdən qorunmaq üçün PeepSo-nu dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What level of permission does an attacker need to exploit CVE-2026-66668?
The attacker needs to have an authenticated subscriber role in the PeepSo plugin.
Which versions of PeepSo are affected by CVE-2026-66668?
The vulnerability affects PeepSo plugin versions 9.0.5.2 and earlier.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.