OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96345

HIGH · CVSS 7.6 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability allows SQL injection in the Estatik plugin for WordPress, affecting versions up to 4.3.5, which could enable attackers to execute arbitrary SQL commands and potentially gain unauthorized access to sensitive data. Organizations using this plugin should prioritize patching or upgrading to mitigate the risk of data breaches and unauthorized database manipulation. Immediate action is recommended for web administrators and security teams managing WordPress sites with the affected plugin.

CVE
CVE-2026-96345
Severity
HIGH
CVSS
7.6
EPSS
0.28%

Original NVD Description

Administrator SQL Injection in Estatik <= 4.3.5 versions.