SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-78468

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

The FluentCRM Pro plugin for WordPress is vulnerable to SQL Injection due to inadequate input escaping and SQL query preparation, affecting all versions up to 3.1.12. This vulnerability allows authenticated attackers with Author-level access or higher to inject malicious SQL queries, potentially leading to the extraction of sensitive database information. WordPress site administrators using this plugin should prioritize applying the latest updates to mitigate this risk.

CVE
CVE-2026-78468
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78270. Reason: This candidate is a reservation duplicate of CVE-2026-78270. Notes: All CVE users should reference CVE-2026-78270 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.