CVE-2026-32471 HIGH

CVE-2026-32471: WordPress ProLancer Element plugin <= 1.4.8 - SQL Injection vulnerability

Vendor Themebing
Product ProLancer Element
Weakness CWE-89 · SQLi
Published August 24, 2026
Last update August 24, 2026

CVSS base score

8.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

Explanation of Vulnerability in Simple Terms

02Summary

ProLancer Element versions up to 1.4.8 contain a SQL injection vulnerability in a database query that accepts user input without proper sanitization. An authenticated user with low privileges can craft a malicious query to read sensitive data from the site's database, including user information and configuration details. The vulnerability also allows limited disruption of database availability.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the site database, including user records and site configuration.

Potential impact on your site

04Site Impact

Unauthorized access to user data, credentials, and site configuration stored in the database.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site; no user interaction required.

Key dates

06Disclosure timeline

August 24, 2026 CVE published

Related vulnerabilities

08Related CVE