CVE-2026-106097

CVE-2026-106097 published: The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabiliti...

View full NVD advisory → ← Back to CVE watch