SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-12512

HIGH · CVSS 8.6 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Quotes Llama WordPress plugin prior to version 3.1.6 is vulnerable to UNION-based SQL injection due to inadequate sanitization of user-supplied parameters in SQL queries. This flaw allows unauthenticated attackers to access sensitive database information, including password hashes, potentially compromising user accounts. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-12512
Severity
HIGH
CVSS
8.6
EPSS
0.27%
WordPress

Original NVD Description

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform UNION-based SQL injection and read arbitrary data from the database, including password hashes.