← العودة للجدول
CVE-2026-18752
CVE-2026-18752 — The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection
📅 2026-09-01
🟡 Medium 🔥 No NVD Exploit WordPress CVSS 6.5

📋 الوصف الكامل

The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQ

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-18752

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.1.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←