CVE WATCH / VULNERABILITY DETAIL

CVE-2026-106097

MEDIUMCVSS 6.8NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabilities; on a WordPress Multisite network those

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-106097 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-106097

MEDIUMCVSS 6.8NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabilities; on a WordPress Multisite network those

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]