SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16539

HIGH · CVSS 8.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The sm page duplicator plugin for WordPress versions up to 1.0.0 is vulnerable to SQL Injection due to insufficient sanitization of stored values in SQL statements during page duplication. This flaw allows users with Editor privileges and higher to manipulate database queries, potentially leading to unauthorized data access or modification. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-16539
Severity
HIGH
CVSS
8.1
EPSS
0.21%
WordPress

Original NVD Description

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.