CVE-2026-66624: WordPress WPMasterToolKit plugin <= 2.22.0 - SQL Injection vulnerability
Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPMasterToolKit pluginto a version that resolves this vulnerability.Fixed in 2.23.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires administrator privileges. It is not described as exploitable by unauthenticated or lower-privileged users.
Is exploitation possible remotely and without user interaction?
Yes. The vector is network-accessible, attack complexity is low, and no user interaction is required. Exploitation still requires high privileges.
Which plugin versions are affected?
WPMasterToolKit versions 2.22.0 and earlier are affected according to the available data.
What is the potential impact if exploited?
The issue can expose highly sensitive information and can have an availability impact. The provided metrics indicate no integrity impact, while the scope may extend beyond the vulnerable component.