
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32539 is a Blind SQL Injection vulnerability (CWE-89) in the PublishPress Revisions WordPress plugin (also known as revisionary). It affects all versions of PublishPress Revisions through 3.7.23 and was published on March 25, 2026, with Patchstack credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical), reflecting its network-accessible, unauthenticated, and no-user-interaction attack profile (Feedly, Patchstack).
The vulnerability stems from improper neutralization of special elements in SQL commands (CWE-89) within the PublishPress Revisions plugin's revisionary component. An unauthenticated, remote attacker can craft malicious network requests that inject SQL syntax into backend database queries, exploiting the lack of proper input sanitization or parameterized queries. Because the injection is "blind," the attacker infers database contents through boolean-based or time-based response differences rather than direct output. No privileges or user interaction are required, and the attack vector is entirely network-based (Feedly, Patchstack).
Successful exploitation allows an unauthenticated attacker to extract sensitive data from the WordPress site's database, including user credentials, email addresses, private post content, and configuration data, resulting in a high confidentiality impact. The CVSS scope is rated as "Changed," indicating the impact extends beyond the plugin itself to the broader database environment. There is also a low availability impact, as malicious queries could degrade database performance or cause disruption (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability has been detected by Qualys (detection ID 531226) and is tracked in the ENISA EUVD under ID EUVD-2026-15913. The EPSS score is approximately 0.03%, indicating a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Feedly).
revisionary plugin that processes unsanitized user input passed to SQL queries.AND SLEEP(5) or conditional AND 1=1/AND 1=2 logic) targeting the vulnerable parameter.sqlmap with blind injection techniques to iteratively extract database schema, table names, and sensitive data (e.g., WordPress wp_users table containing hashed passwords and emails).SLEEP(), AND 1=1, UNION SELECT, OR 1=1).The primary remediation is to update the PublishPress Revisions plugin to a version newer than 3.7.23 as soon as a patched release becomes available from the vendor (Feedly, Patchstack). If the plugin is not critical to operations, consider temporarily disabling it until a patch is released. As an interim measure, deploy a Web Application Firewall (WAF) with SQL injection detection rules to block malicious requests targeting the vulnerable plugin endpoints. Additionally, enforce the principle of least privilege for the WordPress database user account to limit the data accessible via SQL injection.
The vulnerability received coverage from The Hacker Wire and was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of March 16–22, 2026 (Wordfence, The Hacker Wire). Social media mentions were observed on Mastodon and Bluesky shortly after disclosure, consistent with routine CVE announcement activity. No significant vendor statements or notable researcher commentary beyond standard advisory publication have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."