MEDIUM 4.9 NVD
CVE-2026-6295
The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe s
The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that, when the user-supplied value matches the regex ^[(\s]*SELECT\s+, wraps the value in parentheses and embeds it directly into the SQL string without any escaping or quoting. While the normal LIKE code path correctly uses esc_sql($wpdb->esc_like(...)) and wraps the value in single quotes, this branch completely bypasses those protections. Because the attack payload (SELECT ...) contains no single quotes, WordPress's wp_magic_quotes() provides no protection. This makes it possible for authenticated attackers with administrator-level access to inject arbitrary SQL subqueries — including time-based blind payloads — that can be used to extract sensitive information from the database.
References
- https://plugins.trac.wordpress.org/browser/wp-optimizer/tags/2.3.8/modules/supporters/acti
- https://plugins.trac.wordpress.org/browser/wp-optimizer/tags/2.3.8/vendors/wps-framework/Q
- https://plugins.trac.wordpress.org/browser/wp-optimizer/trunk/modules/supporters/activity-
- https://plugins.trac.wordpress.org/browser/wp-optimizer/trunk/vendors/wps-framework/Query.
- https://plugins.trac.wordpress.org/changeset/3508033
This medium severity vulnerability with a CVSS score of 4.9 was published on 2026-09-19 via NVD.
vulnfeed aggregates 14156 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.