What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Philipp Speck WordPress Custom Sidebar wordpress-custom-sidebar allows Blind SQL Injection.This issue affects WordPress Custom Sidebar: from n/a through <= 2.3.
Explanation of Vulnerability in Simple Terms
02Summary
WordPress Custom Sidebar plugin versions 2.3 and earlier contain a SQL injection vulnerability in database queries. An authenticated user with low privileges can craft malicious input to extract sensitive data from the site's database or disrupt database operations. The vulnerability requires a valid WordPress account but no additional user interaction.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site database or cause database errors that disrupt site functionality.
Potential impact on your site
04Site Impact
Attackers with basic WordPress accounts can steal database contents or crash database queries, affecting site stability and exposing user data.
Conditions required to exploit
05Prerequisites
Attacker must have a valid WordPress user account with low-level privileges (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
January 16, 2025
CVE published
May 11, 2026
Record updated