What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sam Perrow Pre* Party Resource Hints.This issue affects Pre* Party Resource Hints: from n/a through 1.8.18.
Explanation of Vulnerability in Simple Terms
02Summary
Pre* Party Resource Hints versions up to 1.8.18 contain a SQL injection vulnerability accessible to high-privilege users. An attacker with administrative access can inject malicious SQL queries through the plugin's input handling. This allows reading or modifying database contents. The vulnerability requires admin-level credentials to exploit.
What an attacker can do
03Attacker Capabilities
Read or modify database contents via SQL injection.
Potential impact on your site
04Site Impact
An admin account compromise could expose or alter your site's database, including user data and post content.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the WordPress site.
Key dates
06Disclosure timeline
December 28, 2023
CVE published
April 28, 2026
Record updated