CVE-2026-62060: WordPress Captivate Sync plugin <= 3.3.2 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through 3.3.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Captivate Sync pluginto a version that resolves this vulnerability.Fixed in 3.3.3
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs high privileges. The vulnerability is network-reachable and has low attack complexity, but it is not indicated as exploitable by an unauthenticated or low-privileged user.
What is the likely impact of successful exploitation?
Successful exploitation can expose sensitive information through blind SQL injection. The reported metrics indicate high confidentiality impact, low availability impact, no integrity impact, and a changed security scope.
Which installations should be considered affected?
Captivate Sync versions through 3.3.2 are affected. The available data does not identify a fixed version or provide configuration-specific exclusions.