rootpwn

critical · CVSS v3 9.1

CVE-2026-94298

The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level us…

Description

The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.

Scores

Severity
critical
CVSS v2
6.4
CVSS v3
9.1
CVSS v4
—
EPSS
—

← All CVEs