logo

High-Severity SQL Injection in Ally WordPress Plugin Threatens 400K Sites

ID: b8de5fa8-d762-5f91-80b4-b494c2e81512

STIX ID: report--b8de5fa8-d762-5f91-80b4-b494c2e81512

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-11

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity SQL Injection (CVE-2026-2413, CVSS 7.5) was found in the Ally WordPress plugin's get_global_remediations() method, allowing unauthenticated time-based blind SQLi to exfiltrate sensitive data. The issue affects sites with the Remediation module active (which requires an Elementor connection), and the vendor patched the vulnerability in version 4.1.0 by using wpdb::prepare() in the JOIN statement; users should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.