CVE-2026-94298None▾ SunlitThe BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-75593High· 7.2BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner
CVE-2025-14650High· 7.3A flaw has been found in itsourcecode Online Cake Ordering System 1.0
CVE-2025-14652High· 7.3A vulnerability was found in itsourcecode Online Cake Ordering System 1.0
CVE-2025-13263Medium· 6.3A vulnerability was identified in SourceCodester Online Magazine Management System 1.0
CVE-2025-11611Medium· 6.3A weakness has been identified in SourceCodester Simple Inventory System 1.0
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0