
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3334 is a SQL Injection vulnerability in the CMS Commander – Manage Multiple Sites plugin for WordPress, affecting all versions up to and including 2.288. The flaw exists in the restore workflow, where the or_blogname, or_blogdescription, and or_admin_email parameters are insufficiently escaped, allowing authenticated attackers with CMS Commander API key access to append malicious SQL queries to existing database queries. It was published on March 21, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, ENISA EUVD).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from insufficient escaping of user-supplied parameters and a lack of prepared statements in the plugin's restore workflow (Backup.php). Specifically, the parameters or_blogname, or_blogdescription, and or_admin_email are passed directly into SQL queries without adequate sanitization, enabling an attacker to append additional SQL clauses. Exploitation requires network access and a valid CMS Commander API key (low-privilege authenticated access), with no user interaction needed. The vulnerable code paths are visible in the plugin source at lib/CMSC/Backup.php lines 1366 and 1639 (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker with API key access to extract sensitive information from the WordPress database, including user credentials, configuration data, and other confidential content. The vulnerability also carries high integrity and availability impact, meaning an attacker could potentially modify or destroy database contents, disrupting site functionality. Given that WordPress databases often contain administrator credentials and personally identifiable information, exploitation could serve as a stepping stone for full site takeover or lateral movement within a hosting environment (Wordfence, ENISA EUVD).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.029% (0.000290), indicating a low current probability of exploitation in the wild. The vulnerability has been detected by Qualys (detection ID 531125) and is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported.
readme.txt.or_blogname, or_blogdescription, or or_admin_email parameters (handled in lib/CMSC/Backup.php).or_blogname=legitimate' UNION SELECT user_login,user_pass,3 FROM wp_users-- -, appending a UNION-based or boolean-based SQL injection payload.', --, UNION, SELECT) in or_blogname, or_blogdescription, or or_admin_email parameters.wp_users or wp_options outside normal application patterns.No patch was available at the time of initial disclosure for versions up to and including 2.288; users should monitor the WordPress plugin repository for an updated release and apply it immediately upon availability. In the interim, restrict CMS Commander API key access to trusted administrators only, and implement network-level controls (e.g., firewall rules or IP allowlisting) to limit access to the CMS Commander API endpoints. If the restore workflow functionality is not actively needed, consider disabling or removing the plugin until a fix is released. Monitor database query logs for anomalous SQL patterns as a detection measure (Wordfence, ENISA EUVD).
Wordfence, which assigned and disclosed the vulnerability, included it in their weekly WordPress vulnerability report for the period of March 16–22, 2026 (Wordfence Blog). RedPacketSecurity shared the CVE on social media shortly after disclosure, contributing to broader community awareness. The vulnerability was also picked up by automated threat intelligence aggregators including VulDB, INCIBE, and The Hacker Wire, reflecting standard industry tracking of WordPress plugin vulnerabilities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."