
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22484 is a SQL Injection vulnerability in the pebas Lisfinity Core WordPress plugin (lisfinity-core), affecting all versions up to and including 1.5.0. The vulnerability stems from improper neutralization of special elements used in SQL commands (CWE-89), allowing unauthenticated network attackers to manipulate database queries. It was published on March 25, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 9.3 (Critical) (Feedly, EUVD).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), where user-supplied input is incorporated into SQL queries without adequate sanitization or parameterization. The attack vector is network-based, requires no authentication and no user interaction, and has low attack complexity — meaning any remote, unauthenticated attacker can craft a malicious HTTP request to exploit the vulnerable plugin endpoint. The changed scope indicator in the CVSS vector suggests the impact extends beyond the plugin itself to the underlying WordPress database. No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly, Patchstack).
Successful exploitation allows an unauthenticated attacker to execute arbitrary SQL commands against the WordPress database, resulting in a high confidentiality impact — including extraction of sensitive data such as user credentials, personal information, and site configuration. There is also a low availability impact, as malicious queries could disrupt database operations or degrade service. Authentication bypass is a potential secondary consequence if credential tables are accessed or manipulated, and lateral movement within a shared hosting environment may be possible depending on database privilege configuration (Feedly).
As of the time of reporting, there is no known public proof-of-concept and no evidence of active in-the-wild exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.021%, indicating a currently low probability of exploitation in the near term. However, the unauthenticated, network-accessible nature of the flaw and its critical CVSS score make it a high-priority patching target (Feedly, EUVD).
The primary remediation is to update the Lisfinity Core plugin to a version beyond 1.5.0 once a patched release is made available by the vendor (pebas). Until a patch is available, administrators should consider disabling the plugin on production sites. Additional mitigations include deploying a Web Application Firewall (WAF) with SQL injection detection rules, enforcing least-privilege database user permissions for the WordPress database account, and monitoring database logs for anomalous or unexpected SQL queries. Implementing parameterized queries and input validation at the application layer is the long-term developer-side fix (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."