CVE-2026-77161
The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the plugin's sync feature to be enabled (options['enabled']) and get_option('egoi_mapping') to be truthy, both of which reflect ordinary configured states for the plugin's core contact mapping functionality.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-89
- Published
- 2026-09-12
- Last modified
- 2026-09-14
Affected products
- egoi Smart Marketing SMS and Newsletters Forms
Weakness type
Related vulnerabilities
- CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability
- CVE-2026-67401 — A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTr
- CVE-2026-61667 — DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval
- CVE-2026-18658 — IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
- CVE-2026-9163 — SQLi in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-86460 — Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
- CVE-2026-82232 — Apache Syncope: SQL injection via sort parameter in Task search
- CVE-2026-77051 — Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search