CVE-2026-54819: WordPress Listdom plugin <= 5.4.0 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection.
This issue affects Listdom: from n/a through 5.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Listdom Pluginto a version that resolves this vulnerability.Fixed in 5.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54819?
CVE-2026-54819 has a critical severity rating of 9.3.
How does CVE-2026-54819 affect the Listdom plugin?
CVE-2026-54819 allows for Blind SQL Injection in the Listdom plugin versions up to 5.4.0.
How do I fix CVE-2026-54819?
To fix CVE-2026-54819, update the Listdom plugin to a version later than 5.4.0.
What types of attacks can CVE-2026-54819 enable?
CVE-2026-54819 can enable attackers to perform SQL injection attacks, potentially allowing them to access sensitive data.
Is CVE-2026-54819 still a risk if I'm using a version higher than 5.4.0?
If you are using a version higher than 5.4.0 of the Listdom plugin, CVE-2026-54819 should not be a risk.