AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15162

HIGH · CVSS 7.5

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Object Sync for Salesforce plugin in WordPress is vulnerable to unauthenticated SQL Injection due to improper handling of the `wordpress_object_type` parameter in its REST API endpoint. This flaw allows attackers to execute arbitrary SQL queries, potentially leading to the extraction of sensitive data, including password hashes, without any authentication required. WordPress site administrators using this plugin should prioritize patching or mitigating this vulnerability to protect their databases from unauthorized access.

CVE
CVE-2026-15162
Severity
HIGH
CVSS
7.5
EPSS
N/A
WordPress

Original NVD Description

The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push class — no capability or nonce — so it is reachable by unauthenticated users. The wordpress_object_type value is concatenated directly into a SQL query (post_type = "$object_type", class-object-sync-sf-wordpress.php:328) and executed via $wpdb->get_results() with no $wpdb->prepare() (:578). Because REST body parameters are not magic-quoted, an attacker can break out of the quoted string and inject arbitrary SQL. This makes it possible for unauthenticated attackers to append additional SQL queries (time-based blind), enabling extraction of sensitive information such as password hashes from the database. Only a valid wordpress_id (e.g. 1) is required — no authentication or Salesforce connection.