← العودة للجدول
CVE-2026-9848
CVE-2026-9848 — The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPr
📅 2026-06-13
🟠 High 🔥 No NVD Exploit Web CVSS 7.5

📋 الوصف الكامل

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks WordPress's `posts_request` filter with `wp_ticket_com_posts_request()`, which calls `emd_author_search_results()` when the current request is an unauthenticated front-end search. That function reads `$query->query_vars[&#

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-9848

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v6.0.4

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←