EIP-2026-113502

PRE-CVE

WordPress Core 3.1.3 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113502. PoCs published by SEC Consult.

AI-analyzed exploit summary This advisory details multiple SQL injection vulnerabilities in WordPress versions 3.1.3 and 3.2-RC1, specifically in the `get_terms()` and `get_bookmarks()` functions. The vulnerabilities allow users with 'Editor' privileges to inject arbitrary SQL commands via the 'orderby' and 'order' parameters.

Description

WordPress Core 3.1.3 - SQL Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by SEC Consult · textwebappsphp
https://www.exploit-db.com/exploits/17465

This advisory details multiple SQL injection vulnerabilities in WordPress versions 3.1.3 and 3.2-RC1, specifically in the `get_terms()` and `get_bookmarks()` functions. The vulnerabilities allow users with 'Editor' privileges to inject arbitrary SQL commands via the 'orderby' and 'order' parameters.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WordPress 3.1.3/3.2-RC1
Auth required
Prerequisites: Editor role access in WordPress
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026