The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 |
Fri, 02 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor. | |
| Title | BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-02T06:00:26.412Z
Reserved: 2026-09-21T09:44:15.108Z
Link: CVE-2026-94298
No data.
Status : Received
Published: 2026-10-02T06:16:43.387
Modified: 2026-10-02T06:16:43.387
Link: CVE-2026-94298
No data.
OpenCVE Enrichment
Updated: 2026-10-02T07:30:07Z
Weaknesses
No weakness.