🔐 CVE Alert

CVE-2026-12983

UNKNOWN 0.0

Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.

Vendor unknown
Product dinatur
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown dinatur

Be the first to know when new unknown vulnerabilities affecting unknown dinatur are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Dinatur
0 ≤ 1.18

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/1369f95a-4ad3-4b0e-a87f-da88d200685e/

Credits

João Ramos Maciel and Theo Antonio da Fonseca WPScan