Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UpSolution UpSolution Core us-core allows Blind SQL Injection.This issue affects UpSolution Core: from n/a through 9.3.
Published: 2026-10-09
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

An improper neutralization of special elements in SQL statements allows an attacker to perform blind SQL injection against the WordPress UpSolution Core plugin. This injection can be used to read, modify, or delete sensitive data stored in the database, or in the worst case, execute arbitrary SQL commands that could compromise the database. This vulnerability is classified under CWE‑89 and carries a CVSS score of 8.5, indicating a high severity risk to confidentiality, integrity, and potentially availability of affected systems.

Affected Systems

The UpSolution UpSolution Core WordPress plugin is affected for all releases from the earliest available version up through 9.3 inclusive. Users who have the plugin installed at versions 9.3 or earlier are vulnerable. The recommendation is to upgrade to at least version 9.3.1, the first release to include the fix.

Risk and Exploitability

The exploitability of this flaw is considered high, though the EPSS score is not available. The lack of a KEV listing does not diminish the risk posed by the high CVSS score. The vulnerability is a blind injection, meaning an attacker would need to infer data through query response characteristics. Attackers could craft malicious input via form fields or URLs that the plugin processes, thereby injecting crafted SQL that the backend executes. Successful exploitation could allow data exfiltration or elevation of privilege within the database.

Generated by OpenCVE AI on October 9, 2026 at 12:10 UTC.

Remediation

Vendor Solution

Update the WordPress UpSolution Core plugin to the latest available version (at least 9.3.1).


OpenCVE Recommended Actions

  • Update the UpSolution Core plugin to version 9.3.1 or later to remove the vulnerability.
  • If an upgrade is not immediately possible, consider disabling or uninstalling the plugin until a patch is available to limit the attack surface.
  • Deploy a web application firewall that blocks or sanitizes suspicious input patterns related to SQL injection for additional protection.

Generated by OpenCVE AI on October 9, 2026 at 12:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UpSolution UpSolution Core us-core allows Blind SQL Injection.This issue affects UpSolution Core: from n/a through 9.3.
Title WordPress UpSolution Core plugin <= 9.3 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:17.308Z

Reserved: 2026-09-22T09:18:20.380Z

Link: CVE-2026-95610

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:43.330

Modified: 2026-10-09T10:16:43.330

Link: CVE-2026-95610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:15:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')