
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57643 is a SQL injection vulnerability in the WP Post Author WordPress plugin by AF Themes, affecting versions 3.9.1 and earlier. It allows authenticated users with contributor-level privileges to inject malicious SQL code through an unprotected input, enabling unauthorized database access. The vulnerability was published on June 26, 2026, and assigned a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is incorporated into SQL queries without adequate sanitization or parameterization (GitHub Advisory). An attacker with a contributor-level WordPress account can craft malicious SQL payloads through an unprotected plugin input, which are then executed directly against the underlying database over the network. No user interaction is required beyond the attacker's own authenticated session, and attack complexity is low. The scope is marked as Changed, indicating the impact extends beyond the vulnerable component itself to the database layer.
Successful exploitation allows an authenticated contributor to read sensitive data from the WordPress database — including user credentials, personal information, and site configuration — and cause limited service disruption through resource exhaustion or database manipulation (GitHub Advisory, Feedly). Confidentiality impact is rated High, while integrity impact is None and availability impact is Low. Exposed data could facilitate further attacks such as account takeover or lateral movement within the hosting environment.
', --, UNION, SELECT, SLEEP).Update the WP Post Author plugin to a version newer than 3.9.1 as soon as a patched release is available from AF Themes (GitHub Advisory). As an interim measure, restrict contributor account creation and access to trusted users only, and audit existing contributor accounts for unauthorized access. Deploying a Web Application Firewall (WAF) with SQL injection detection rules can help block exploitation attempts. Monitor database activity logs for anomalous query patterns indicative of SQL injection (Feedly).
Wordfence included CVE-2026-57643 in its weekly WordPress vulnerability report for the period of June 22–28, 2026, highlighting it as part of a broader set of plugin vulnerabilities (Feedly). The vulnerability was reported and assigned by Patchstack, which maintains a dedicated WordPress vulnerability database entry for this issue. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregator reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."