Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94298 | 1 Wordpress-extensions | 1 Buildkit | 2026-10-02 | 6.2 Medium |
| The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor. | ||||
| CVE-2026-102379 | 2 Villatheme, Wordpress-extensions | 2 Buildkit – Product Builder For Woocommerce – Custom Pc Builder, Buildkit-product Builder For Woocommerce-custom Pc Builder | 2026-10-01 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28. | ||||
Page 1 of 1.