{"id":"CVE-2026-106097","title":"The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-admin…","summary":"The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-admin…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-89"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:08.503","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106097","references":[{"url":"https://wpscan.com/vulnerability/f5206366-2e9c-42d5-90b9-ddfaf39aa02f/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00156,"epssPercentile":0.042,"ingestedAt":"2026-10-09T07:28:22.265Z","slug":"CVE-2026-106097","body":"## Overview\n\nThe Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabilities; on a WordPress Multisite network those belong to subsite Administrators, allowing a subsite Administrator who is not a network Super Admin to perform UNION-based SQL injection against shared network tables and disclose network-wide data such as other users' password hashes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":218536,"id":"CVE-2026-106097","ts":1791561811508,"field":"cvss","old":null,"new":"6.8"},{"seq":218535,"id":"CVE-2026-106097","ts":1791561811508,"field":"severity","old":"none","new":"medium"}]}