Description
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Stored SQL Injection via contributor data
Action: Immediate Patch
AI Analysis

Impact

The BuildKit WordPress plugin before 1.0.29 fails to sanitize and escape data submitted by contributor‑level users. The list_content parameter is stored directly and later incorporated into a database query without proper escaping. A malicious contributor can inject SQL that executes when the stored content is published and viewed by any visitor, potentially exposing, modifying, or deleting data in the site database.

Affected Systems

Any WordPress installation using the BuildKit plugin version earlier than 1.0.29 is affected. The vulnerability exists in the plugin code managing the list_content field and requires that a user has the Contributor role.

Risk and Exploitability

Because the flaw is a stored SQL injection, exploitation requires the attacker to have contributor privileges, which is a relatively low‑privilege level commonly granted for content authors. Once injected, the associated SQL runs with the privileges of the web application’s database user. No public exploit is reported, and the EPSS score is not available, making it uncertain how often the vulnerability will be targeted. The lack of a KEV designation means no known public exploitation has been documented. Nonetheless, the high potential impact and availability of an unauthenticated view endpoint make this a high‑risk issue, especially in environments with sensitive data.

Generated by OpenCVE AI on October 2, 2026 at 07:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update BuildKit to version 1.0.29 or later
  • Disable or remove the BuildKit plugin if an update is not feasible
  • Restrict the Contributor role or remove contributor privileges from untrusted users
  • Apply additional input validation or use parameterized queries to ensure list_content is safely handled

Generated by OpenCVE AI on October 2, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Fri, 02 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
Title BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T06:00:26.412Z

Reserved: 2026-09-21T09:44:15.108Z

Link: CVE-2026-94298

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T06:16:43.387

Modified: 2026-10-02T06:16:43.387

Link: CVE-2026-94298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T07:30:07Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')