High-Severity SQL Injection in Ally WordPress Plugin Threatens 400K Sites
ID: b8de5fa8-d762-5f91-80b4-b494c2e81512
STIX ID: report--b8de5fa8-d762-5f91-80b4-b494c2e81512
Feed Name: securityonline.info
Threat Score
A high-severity SQL Injection (CVE-2026-2413, CVSS 7.5) was found in the Ally WordPress plugin's get_global_remediations() method, allowing unauthenticated time-based blind SQLi to exfiltrate sensitive data. The issue affects sites with the Remediation module active (which requires an Elementor connection), and the vendor patched the vulnerability in version 4.1.0 by using wpdb::prepare() in the JOIN statement; users should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
