CVE-2026-96827: WordPress Admin Notices Manager plugin <= 1.6.0 - SQL Injection vulnerability
Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Admin Notices Manager pluginto a version that resolves this vulnerability.Fixed in 1.6.1
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs administrator-level privileges in WordPress. The supplied CVSS vector lists PR:H, so unauthenticated and low-privileged users are not indicated as able to exploit it.
Is user interaction required for exploitation?
No. The CVSS vector specifies UI:N, indicating that exploitation does not require another user to take an action.
Which installations are affected?
WordPress sites using Admin Notices Manager version 1.6.0 or earlier are affected according to the available data.
What impact could successful exploitation have?
The CVSS vector indicates high confidentiality impact and low availability impact, with scope changed. Integrity impact is listed as none.