Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through 3.3.2.
Published: 2026-10-01
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper handling of input that can be incorporated into an SQL command, enabling blind SQL injection. An attacker can send crafted requests that cause the plugin to execute unauthorized SQL statements, potentially reading, modifying, or deleting data from the underlying database. The impact is therefore a compromise of data confidentiality, integrity, and availability for the affected WordPress site.

Affected Systems

WordPress sites that use the Captivate Sync plugin from captivateaudio’s Captivate Sync, specifically any deployment using versions up to and including 3.3.2. No other vendors or products are explicitly affected.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity with a significant risk of exploitation. The EPSS score is not available, so the exact exploitation likelihood is uncertain, but the vulnerability remains a serious concern. It is not listed in the CISA KEV catalog, yet the blind nature of the SQL injection means attackers could extract data without immediate detection. The likely attack vector is via web requests to the plugin’s endpoints that do not properly sanitize input.

Generated by OpenCVE AI on October 1, 2026 at 15:31 UTC.

Remediation

Vendor Solution

Update the WordPress Captivate Sync plugin to the latest available version (at least 3.3.3).


OpenCVE Recommended Actions

  • Update the Captivate Sync plugin to the latest version (3.3.3 or newer).
  • Restore a recent backup of the WordPress database to mitigate potential data loss.
  • Monitor database activity and web traffic for anomalous queries, and apply WAF rules to block suspicious inputs.

Generated by OpenCVE AI on October 1, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through 3.3.2.
Title WordPress Captivate Sync plugin <= 3.3.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T13:12:51.056Z

Reserved: 2026-07-13T06:14:43.014Z

Link: CVE-2026-62060

cve-icon Vulnrichment

Updated: 2026-10-01T13:12:46.746Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T13:17:10.140

Modified: 2026-10-01T14:34:35.357

Link: CVE-2026-62060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:45:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')