critical · CVSS v3 9.1
CVE-2026-94298
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level us…
Description
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
Scores
- Severity
- critical
- CVSS v2
- 6.4
- CVSS v3
- 9.1
- CVSS v4
- —
- EPSS
- —