Description
Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
Published: 2026-09-17
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The PublishPress Series plugin for WordPress can be exploited by authenticated administrators to inject arbitrary SQL commands. This flaw, classified as CWE-89, enables the attacker to read or modify data stored in the WordPress database, potentially exposing sensitive content or corrupting it.

Affected Systems

The vulnerability is present in all installations of the PublishPress Series plugin with a version of 3.1.3 or earlier. No other WordPress core or plugin versions are mentioned as affected.

Risk and Exploitability

The CVSS base score of 7.6 reflects a medium‑to‑high severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability has not been reported in the CISA KEV catalog, indicating no confirmed active exploitation. Attackers need an authenticated administrator account and knowledge of the plugin’s database structure to conduct the injection, which could lead to unauthorized data access or modification.

Generated by OpenCVE AI on September 17, 2026 at 22:10 UTC.

Remediation

Vendor Solution

Update the WordPress PublishPress Series Plugin to the latest available version (at least 3.1.4).


OpenCVE Recommended Actions

  • Update the PublishPress Series plugin to version 3.1.4 or newer on all WordPress sites that host the plugin.
  • Restrict the database account used by WordPress to the minimum privileges required for content management, reducing the impact of any injected statements.
  • Implement monitoring of database activity and consider deploying a web application firewall that blocks suspicious SQL patterns to detect and mitigate exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Publishpress
Publishpress publishpress Series
Wordpress
Wordpress wordpress
Vendors & Products Publishpress
Publishpress publishpress Series
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
Title WordPress PublishPress Series plugin <= 3.1.3 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Publishpress Publishpress Series
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T02:23:16.128Z

Reserved: 2026-07-27T14:00:26.966Z

Link: CVE-2026-66630

cve-icon Vulnrichment

Updated: 2026-09-19T02:23:11.817Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:19.983

Modified: 2026-09-19T03:17:15.197

Link: CVE-2026-66630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:15:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')