🔴 《严重安全漏洞:CVE-2026-12877》

CVSS 评分: 严重(9.1)  状态: Deferred  发布时间: 2026-07-24


漏洞描述

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.


🔍 技术细节

字段
CVE ID CVE-2026-12877
CVSS 评分 9.1 🔴
严重程度 严重
CVSS 向量 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE 分类 CWE-287
发布时间 2026-07-24
最后更新 2026-07-24
状态 Deferred
数据来源 contact@wpscan.com

🔗 参考链接