CVE-2026-95593: WordPress Ultimeter plugin <= 3.0.8 - SQL Injection vulnerability
Published Sep 23, 2026
·Updated
Editor SQL Injection in Ultimeter <= 3.0.8 versions.
Affected Software
1 affected component
WordPress Ultimeter<=3.0.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimeter pluginto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability is described as an editor-level SQL injection, so an attacker needs Editor privileges in WordPress. The attack vector is network-based and does not require user interaction.
2
What is the likely security impact?
The supplied severity vector indicates high confidentiality impact and low availability impact. It indicates no integrity impact, while the scope may change.
3
How can I determine whether my site is affected?
Review the installed Ultimeter plugin version. Versions 3.0.8 and earlier are identified as affected.