CVE-2026-17576

CVE-2026-17576 published: The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL...

View full NVD advisory → ← Back to CVE watch