CVE-2026-66668: WordPress Community by PeepSo plugin <= 9.0.5.2 - SQL Injection vulnerability
Published Aug 19, 2026
·Updated
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
Affected Software
1 affected component
WordPress Community by PeepSo plugin<=9.0.5.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Community by PeepSo Pluginto a version that resolves this vulnerability.Fixed in 9.0.5.3
Event History
Aug 19, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Subscriber-level access to a WordPress site using an affected Community by PeepSo version. No user interaction is required, and the attack can be performed over the network.
2
What could successful exploitation allow?
The vulnerability has high confidentiality impact and low availability impact. Its scope is changed, meaning the impact can extend beyond the vulnerable component's security authority.
3
Which versions are affected?
Community by PeepSo versions 9.0.5.2 and earlier are affected.