---
id: CVE-2026-96826
title: >-
  Improper Neutralization of Special Elements used in an SQL Command ('SQL
  Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind
  SQL Injection.


  This issue affects W4 Post List: from n/a through 3.0.6.
summary: >-
  Improper Neutralization of Special Elements used in an SQL Command ('SQL
  Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind
  SQL Injection.


  This issue affects W4 Post List: from n/a through 3.0.6.
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'
cwe:
  - CWE-89
vendor: Shazzad Hossain Khan
product: w4-post-list
affected:
  - w4-post-list >= n/a <= 3.0.6
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:00:47.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96826'
references:
  - url: >-
      https://patchstack.com/database/wordpress/plugin/w4-post-list/vulnerability/wordpress-w4-post-list-plugin-3-0-6-sql-injection-vulnerability?_s_id=cve
    label: audit@patchstack.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T10:41:56.285021Z'
ingestedAt: '2026-09-23T20:32:10.757Z'
epss: 0.00226
epssPercentile: 0.11871
---

## Overview

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Injection.

This issue affects W4 Post List: from n/a through 3.0.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
