๐Ÿ” CVE Alert

CVE-2026-94298

UNKNOWN 0.0

BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.

Vendor unknown
Product buildkit
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown buildkit

Be the first to know when new unknown vulnerabilities affecting unknown buildkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / BuildKit
0 < 1.0.29

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6f6c8718-7e7e-4700-a4c2-ee177c44b7ea/

Credits

Naiches WPScan