CVE-2026-94298
BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
| Vendor | unknown |
| Product | buildkit |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown buildkit
Be the first to know when new unknown vulnerabilities affecting unknown buildkit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / BuildKit
0 < 1.0.29
References
Credits
Naiches WPScan