logo

SQL Injection Vulnerability in Ally WordPress Plugin Exposes 200K+ Sites

ID: 925afdd8-7885-5d76-ad11-a097364ff65e

STIX ID: report--925afdd8-7885-5d76-ad11-a097364ff65e

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-03-13

Date Updated: 2026-04-22

Author: Waqas

...
...

A critical SQL injection vulnerability (CVE-2026-2413) in the Ally WordPress plugin — installed on ~400,000 sites — allows unauthenticated attackers to perform time‑based blind SQLi and extract sensitive database records; a patch (v4.1.0) was released on Feb 23 but an estimated 60% of installations (~200,000 sites) remained unpatched as of March 11, creating a large window for automated mass exploitation. Site owners should update immediately and audit stored user data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.