CVE-2026-96345: WordPress Estatik plugin <= 4.3.5 - SQL Injection vulnerability
Administrator SQL Injection in Estatik <= 4.3.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Estatik pluginto a version that resolves this vulnerability.Fixed in 4.3.6
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker needs administrator-level privileges in the affected WordPress environment. The issue is remotely exploitable over the network, requires low attack complexity, and does not require user interaction.
How can I determine whether my site is affected?
Check whether the Estatik plugin is installed and identify its version. Versions 4.3.5 and earlier are affected according to the available information.
What impact could successful exploitation have?
Successful exploitation can expose highly sensitive information and can affect components beyond the initially vulnerable security authority. Availability impact is rated low, while no integrity impact is specified.