SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-12983

HIGH · CVSS 8.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Dinatur WordPress plugin versions up to 1.18 are vulnerable to SQL injection due to inadequate sanitization and escaping of user input, enabling unauthenticated users to execute malicious SQL queries. Additionally, the plugin allows unauthorized database table truncation, which can lead to data loss for any unauthenticated visitor. WordPress site administrators using this plugin should prioritize immediate updates or mitigations to protect against these critical vulnerabilities.

CVE
CVE-2026-12983
Severity
HIGH
CVSS
8.6
EPSS
0.32%
WordPress

Original NVD Description

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.