First published: Sat Mar 15 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aldo Latino PrivateContent | <=8.11.4 | |
WordPress PrivateContent | <=8.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26976 is classified as a critical SQL Injection vulnerability, which could allow attackers to execute arbitrary SQL commands on the database.
To fix CVE-2025-26976, you should update Aldo Latino PrivateContent to the latest version that addresses this vulnerability.
CVE-2025-26976 affects all versions of Aldo Latino PrivateContent from n/a through 8.11.4.
Due to CVE-2025-26976, attackers can perform unauthorized actions on the database, potentially leading to data breaches.
Yes, CVE-2025-26976 is specific to Aldo Latino PrivateContent as well as the WordPress version of the plugin.