Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5.
Published: 2026-10-05
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Update Plugin
AI Analysis

Impact

The vulnerability is an improper neutralization of special elements used in an SQL command, allowing a blind SQL injection into the Sirv WordPress plugin. An attacker who can supply input that reaches the plugin's SQL queries can read or modify database contents, potentially compromising the confidentiality and integrity of sensitive data stored by the site.

Affected Systems

WordPress sites using the Sirv plugin, with affected plugin versions 8.2.5 and prior. The vendor is Sirv and the product is the Sirv WordPress plugin.

Risk and Exploitability

The CVSS base score of 8.5 indicates high severity, and the EPSS score is currently unavailable, meaning the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, starting from a web request to the WordPress site that can manipulate the plugin’s SQL queries.

Generated by OpenCVE AI on October 5, 2026 at 10:23 UTC.

Remediation

Vendor Solution

Update the WordPress Sirv plugin to the latest available version (at least 8.2.6).


OpenCVE Recommended Actions

  • Update the WordPress Sirv plugin to version 8.2.6 or later.
  • Configure a Web Application Firewall to block suspicious SQL injection patterns targeting the Sirv plugin’s endpoints.
  • Monitor web server and application logs for failed or suspicious database query attempts that may indicate exploitation attempts.

Generated by OpenCVE AI on October 5, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5.
Title WordPress Sirv plugin <= 8.2.5 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T08:57:17.337Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104389

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:07.657

Modified: 2026-10-05T09:17:07.657

Link: CVE-2026-104389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')