Loading market data...
← Back to CVE feed

CVE-2026-14238

UNKNOWN View on NVD ↗

Description

The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.

Published: Aug 10, 2026 07:16 UTC Modified: Aug 10, 2026 07:16 UTC