CVE-2026-108124: WordPress Post Author Authenticated SQLi
Published Oct 9, 2026
·Updated
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author.
This issue affects wp-post-author before 4.1.0.
Affected Software
0 affected components
Event History
Oct 9, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
The issue affects wp-post-author versions before 4.1.0. The provided data does not identify any WordPress core version requirements or affected configuration details.
2
What level of access does an attacker need?
Exploitation requires high privileges (PR:H). The vector is network-accessible and does not require user interaction, but the provided data does not specify the exact WordPress role or capability required.
3
What is the potential impact?
The CVSS vector indicates high confidentiality impact, with no integrity or availability impact. Successful exploitation could expose data accessible through the vulnerable SQL query.