CVE-2026-22484
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22484 is a SQL Injection vulnerability in the pebas Lisfinity Core WordPress plugin (lisfinity-core), affecting all versions up to and including 1.5.0. The vulnerability stems from improper neutralization of special elements used in SQL commands (CWE-89), allowing unauthenticated network attackers to manipulate database queries. It was published on March 25, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 9.3 (Critical) (Feedly, EUVD).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), where user-supplied input is incorporated into SQL queries without adequate sanitization or parameterization. The attack vector is network-based, requires no authentication and no user interaction, and has low attack complexity — meaning any remote, unauthenticated attacker can craft a malicious HTTP request to exploit the vulnerable plugin endpoint. The changed scope indicator in the CVSS vector suggests the impact extends beyond the plugin itself to the underlying WordPress database. No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly, Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary SQL commands against the WordPress database, resulting in a high confidentiality impact — including extraction of sensitive data such as user credentials, personal information, and site configuration. There is also a low availability impact, as malicious queries could disrupt database operations or degrade service. Authentication bypass is a potential secondary consequence if credential tables are accessed or manipulated, and lateral movement within a shared hosting environment may be possible depending on database privilege configuration (Feedly).

Exploitability

As of the time of reporting, there is no known public proof-of-concept and no evidence of active in-the-wild exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.021%, indicating a currently low probability of exploitation in the near term. However, the unauthenticated, network-accessible nature of the flaw and its critical CVSS score make it a high-priority patching target (Feedly, EUVD).

Mitigation and workarounds

The primary remediation is to update the Lisfinity Core plugin to a version beyond 1.5.0 once a patched release is made available by the vendor (pebas). Until a patch is available, administrators should consider disabling the plugin on production sites. Additional mitigations include deploying a Web Application Firewall (WAF) with SQL injection detection rules, enforcing least-privilege database user permissions for the WordPress database account, and monitoring database logs for anomalous or unexpected SQL queries. Implementing parameterized queries and input validation at the application layer is the long-term developer-side fix (Feedly, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management