← Terug naar overzicht

A critical unauthenticated SQL injection vulnerability has been identified in the Beautiful Taxonomy Filters WordPress plugin, affecting versions 2.4.6 and earlier. The vulnerability allows unauthenticated attackers to perform SQL injection attacks, potentially exposing sensitive database information or enabling full database compromise. No authentication is required to exploit this flaw, significantly increasing the risk profile. The issue is tracked as CVE-2026-78288 and has been published on the National Vulnerability Database. A patch or updated version beyond 2.4.6 is recommended to remediate the vulnerability. The vulnerability has also been documented by Patchstack in their WordPress vulnerability database. Site administrators running the affected plugin should update immediately to mitigate risk.

Affected products

  • Beautiful Taxonomy Filters WordPress Plugin <= 2.4.6

Related CVE's

  • CVE-2026-78288

Categories

  • Database & Storage
  • Web Technologies