Description
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated SQL Injection leading to data exposure
Action: Immediate Patch
AI Analysis

Impact

The Tz Weekly Radio Schedule WordPress plugin through version 1.8.1 does not sanitize or escape the 'week' parameter used in a vulnerable AJAX action, allowing attackers to inject arbitrary SQL statements and read sensitive database content. This flaw is a classic input validation weakness classified as CWE-89 and can result in unauthorized disclosure of user data, site configurations, and potentially full database compromise.

Affected Systems

The vulnerability affects the WordPress plugin Tz Weekly Radio Schedule versions up to and including 1.8.1. There are no other vendors or products listed; the issue is specific to this plugin as noted by the CWE entry.

Risk and Exploitability

The CVSS score of 8.6 highlights a high severity for a vulnerability that could allow an unauthenticated attacker to inject SQL via the 'week' parameter. The EPSS score of less than 1% suggests that, at the time of analysis, the likelihood of exploitation is low. The flaw is not listed in CISA KEV. Based on the description, the vulnerable AJAX endpoint can be accessed by anyone over HTTP without authentication, indicating a remote attack vector.

Generated by OpenCVE AI on September 19, 2026 at 19:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Tz Weekly Radio Schedule plugin to a version newer than 1.8.1 or remove the plugin if no update is available.
  • If an upgrade is not feasible immediately, disable the vulnerable AJAX action that accepts the 'week' parameter for unauthenticated users by configuring the plugin code or web server to block that request.
  • Apply general WordPress security hardening: restrict AJAX access to authenticated users, use secure database credentials, and monitor database query logs for suspicious activity.

Generated by OpenCVE AI on September 19, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions tz Weekly Radio Schedule
Vendors & Products Wordpress-extensions
Wordpress-extensions tz Weekly Radio Schedule

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Title Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week
References

Subscriptions

Wordpress-extensions Tz Weekly Radio Schedule
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:10:11.521Z

Reserved: 2026-09-09T08:25:02.120Z

Link: CVE-2026-87774

cve-icon Vulnrichment

Updated: 2026-09-18T11:02:31.103Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:40.637

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-87774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:21:47Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')