CVE-2026-108125: WordPress Post Author Authenticated SQLi
Published Oct 9, 2026
·Updated
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author.
This issue affects wp-post-author version 4.0.0 prior to 4.1.0.
Affected Software
1 affected component
wp-post-author>=4.0.0<4.1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wp-post-authorto a version that resolves this vulnerability.Fixed in 4.1.0
Event History
Oct 9, 2026
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
DescriptionWeakness
Frequently Asked Questions
1
Which installations are affected?
Installations running wp-post-author version 4.0.0 before 4.1.0 are affected.
2
What level of access does an attacker need?
The vulnerability is described as authenticated SQL injection, so an attacker needs authenticated access. The provided data does not specify which user role or capability is required.