CVE-2026-42416: WordPress UDesign Core plugin <= 4.15.0 - SQL Injection vulnerability
Published Oct 6, 2026
·Updated
Subscriber SQL Injection in UDesign Core <= 4.15.0 versions.
Affected Software
1 affected component
UDesign UDesign Core<=4.15.0
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who would need to exploit this issue?
An attacker needs a low-privileged authenticated account, consistent with subscriber-level access. The attack can be performed remotely and does not require user interaction.
2
What is the potential impact of successful exploitation?
The severity vector indicates high confidentiality impact and low availability impact, with the vulnerability able to affect resources beyond the vulnerable component's security scope. Integrity impact is listed as none.
3
Which deployments should be prioritized for remediation?
UDesign Core installations at version 4.15.0 or earlier should be treated as affected, particularly where subscriber accounts can be created or obtained by untrusted users.