Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blind SQL Injection.This issue affects CWS SVGicons: from n/a through <= 1.5.5.
Published: 2026-07-13
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CWS SVGicons plugin for WordPress contains a blind SQL injection vulnerability due to improper neutralization of special characters used in an SQL command. The flaw allows an attacker to inject arbitrary SQL code into database queries executed by the plugin, potentially leading to data exfiltration, unauthorized data modification, or data deletion. This weakness is classified as CWE‑89, a high‑severity issue that directly undermines the confidentiality, integrity, and availability of the affected WordPress site's database.

Affected Systems

All WordPress installations that have the CreativeWS CWS SVGicons plugin installed at version 1.5.5 or earlier are vulnerable. The plugin’s public documentation lists no later versions as affected, and no other products are indicated by the CNA. Therefore, any site using this plugin at or below the cited version should be considered at risk.

Risk and Exploitability

The CVSS score of 8.5 signifies a EPSS score of less than 1% indicates a very low probability of exploitation as of the latest data, and the vulnerability is not yet present in the CISA KEV catalog. Because the vulnerability is blind, an attacker would need to send crafted inputs to the plugin’s database queries in order to infer data, but the CVE does not disclose a specific entry point or protocol, so the precise attack vector remains unspecified in public sources.

Generated by OpenCVE AI on August 1, 2026 at 10:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CWS SVGicons plugin to the latest available version when a fix is released.
  • If no patch is available, deactivate or remove the plugin from the WordPress installation to eliminate the attack surface.
  • Ensure that all plugins and core WordPress updates are applied promptly, and monitor vendor advisories for any additional patch releases.

Generated by OpenCVE AI on August 1, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Creativews
Creativews cws Svgicons
Wordpress
Wordpress wordpress
Vendors & Products Creativews
Creativews cws Svgicons
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blind SQL Injection.This issue affects CWS SVGicons: from n/a through <= 1.5.5.
Title WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Creativews Cws Svgicons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:31:32.655Z

Reserved: 2026-06-25T08:05:02.626Z

Link: CVE-2026-57787

cve-icon Vulnrichment

Updated: 2026-07-13T13:28:40.688Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')