CVE-2026-106097: Code Snippets < 3.10.0 - Admin+ SQLi in Migration Importers Leading to Network-Wide Credential Disclosure (Multisite)
The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabilities; on a WordPress Multisite network those belong to subsite Administrators, allowing a subsite Administrator who is not a network Super Admin to perform UNION-based SQL injection against shared network tables and disclose network-wide data such as other users' password hashes.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue in a WordPress Multisite deployment?
A subsite Administrator with site-administration capabilities can access the affected snippet-migration import endpoints. The attacker does not need to be a network Super Admin.
What data could be exposed if the issue is exploited?
The SQL injection can be used in a UNION-based attack against shared network tables. This may disclose network-wide data, including other users' password hashes.
Are single-site WordPress installations identified as affected?
The provided information specifically describes impact in WordPress Multisite, where subsite Administrators can query shared network tables. It does not state whether single-site installations are affected.
Which plugin versions are vulnerable?
Code Snippets versions before 3.10.0 are affected.