Description
Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
Published: 2026-09-17
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

An administrator-level SQL Injection flaw exists in WordPress WPMasterToolKit plugin versions 2.22.0 and earlier. The vulnerability permits an authenticated attacker with plugin administrative rights to inject arbitrary SQL statements, potentially exposing or modifying sensitive database contents and compromising data confidentiality and integrity.

Affected Systems

The affected product is Ludwig You:WPMasterToolKit for WordPress. Any deployment using plugin version 2.22.0 or older is vulnerable.

Risk and Exploitability

The CVSS score of 7.6 classifies the issue as High severity, while the EPSS score is not available, indicating uncertainty about current exploitation rates. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires administrative access to the plugin through the WordPress dashboard; attackers may therefore need credentials or exploit a separate configuration weakness to gain that access.

Generated by OpenCVE AI on September 17, 2026 at 22:11 UTC.

Remediation

Vendor Solution

Update the WordPress WPMasterToolKit Plugin to the latest available version (at least 2.23.1).


OpenCVE Recommended Actions

  • Update the WordPress WPMasterToolKit plugin to version 2.23.1 or newer on all sites.
  • Restrict administrator access to the plugin until the update can be applied, or temporarily disable the plugin on production sites.
  • Review WordPress logs and database integrity to ensure no unauthorized queries were executed before applying the patch.

Generated by OpenCVE AI on September 17, 2026 at 22:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Ludwig You
Ludwig You wpmastertoolkit
Wordpress
Wordpress wordpress
Vendors & Products Ludwig You
Ludwig You wpmastertoolkit
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
Title WordPress WPMasterToolKit plugin <= 2.22.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Ludwig You Wpmastertoolkit
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-17T19:21:47.942Z

Reserved: 2026-07-27T14:00:26.966Z

Link: CVE-2026-66624

cve-icon Vulnrichment

Updated: 2026-09-17T17:10:29.237Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:18.970

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-66624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:21Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')