CVE-2026-73388: WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Nikstore Core pluginto a version that resolves this vulnerability.Fixed in 1.5
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior access. The network attack vector indicates it can be targeted remotely.
Which installations are affected?
Nikstore Core versions 1.5 and earlier are identified as affected. The provided data does not state whether any particular WordPress configuration or feature must be enabled.
What is the potential impact of successful exploitation?
The vulnerability is rated critical with high confidentiality impact and low availability impact. Its scope is changed, meaning the reported impact can extend beyond the vulnerable component's security authority.