CVE-2025-26886: WordPress PublishPress Authors plugin <= 4.7.3 - SQL Injection vulnerability
Published Mar 15, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Authors publishpress-authors allows SQL Injection.This issue affects PublishPress Authors: from n/a through <= 4.7.3.
Affected Software
1 affected component
PublishPress PublishPress Authors<=4.7.3
Remediation
Information
Update the WordPress PublishPress Authors wordpress plugin to the latest available version (at least 4.7.4).
Event History
Mar 15, 2025
CVE Published
via MITRE·09:57 PM
Data Sourced
via MITRE·09:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26886?
CVE-2025-26886 has a high severity rating due to its potential for SQL Injection exploitation.
2
How do I fix CVE-2025-26886?
To fix CVE-2025-26886, update the PublishPress Authors plugin to version 4.7.4 or later.
3
What versions of PublishPress Authors are affected by CVE-2025-26886?
CVE-2025-26886 affects all versions of PublishPress Authors from n/a through 4.7.3.
4
What type of vulnerability is CVE-2025-26886?
CVE-2025-26886 is classified as an SQL Injection vulnerability.
5
What impact can CVE-2025-26886 have on my website?
Exploiting CVE-2025-26886 can allow attackers to execute arbitrary SQL commands, potentially compromising database integrity.