cleantalk
Vulnerabilities and Security Researches

Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors, CVE-2025-26886

CVE, Research URL

CVE-2025-26886

Published on
Mar 16, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Authors allows SQL Injection. This issue affects PublishPress Authors: from n/a through 4.7.3.
Affected versions
Min -, max 4.7.4.
Status
vulnerable