Description
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Published: 2026-08-13
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated SQL injection flaw present in WordPress/Listdom plugin versions 5.6.0 and older. Through improperly sanitized user input, an attacker can inject arbitrary SQL statements that are executed by the underlying database. This weakness can compromise database confidentiality and integrity and may provide a foothold for further exploitation such as remote code execution or privilege escalation. The flaw is characterized by CWE‑89.

Affected Systems

The affected component is the Webilia Inc. Listdom plugin for WordPress. Any site running Listdom 5.6.0 or earlier is vulnerable. No specific WordPress core versions are mentioned; the plugin alone is required to be updated. Version 5.7.0 or later contains the fix.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity, and the lack of an EPSS score means the current exploitation probability is not quantified, but the vulnerability is not known to be exploited in the wild (not listed in KEV). Attackers can leverage the vulnerability from any user without authentication, which means the attack vector is remote and straightforward. In practice, an attacker can gain full control over the affected database.

Generated by OpenCVE AI on August 13, 2026 at 15:54 UTC.

Remediation

Vendor Solution

Update the WordPress Listdom Plugin to the latest available version (at least 5.7.0).


OpenCVE Recommended Actions

  • Update the Listdom plugin to version 5.7.0 or newer on all WordPress installations.
  • Configure automatic updates for the plugin and regularly review plugin versions to prevent re‑introduction of the vulnerability.
  • If automatic updates cannot be enabled, manually audit all sites to confirm that no instance of the vulnerable plugin version remains active.

Generated by OpenCVE AI on August 13, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Title WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:18:53.854Z

Reserved: 2026-07-13T06:13:50.885Z

Link: CVE-2026-61969

cve-icon Vulnrichment

Updated: 2026-08-13T15:18:47.089Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:03.080

Modified: 2026-08-13T16:18:15.660

Link: CVE-2026-61969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:00:11Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')