{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/object-sync-for-salesforce/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-15162"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Object Sync for Salesforce"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sql-injection","wordpress","cve-2026-15162"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Object Sync for Salesforce plugin for WordPress is vulnerable to an unauthenticated SQL injection via the 'wordpress_object_type' parameter within the REST API endpoint '/wp-json/object-sync-for-salesforce/push/'. The vulnerability exists because the plugin's permission callback, 'can_process()', fails to enforce nonce or capability checks, making the route accessible to any unauthenticated user. The input is then concatenated directly into a SQL query within the 'class-object-sync-sf-wordpress.php' file at line 328 and executed via '$wpdb-\u0026gt;get_results()' without utilizing '$wpdb-\u0026gt;prepare()'. Because WordPress REST API body parameters lack sanitization, an attacker can break out of the string context and inject arbitrary SQL commands, potentially leading to database exfiltration, including the dumping of user password hashes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to execute arbitrary SQL queries against the underlying WordPress database. This can result in the exfiltration of sensitive configuration data, user account details, and password hashes, leading to full site compromise or account takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the Object Sync for Salesforce plugin to the latest patched version immediately to remediate CVE-2026-15162.\u003c/li\u003e\n\u003cli\u003eImplement the provided Sigma rule at the webserver layer to detect and block exploitation attempts targeting the specific vulnerable endpoint.\u003c/li\u003e\n\u003cli\u003eAudit access logs for anomalous POST requests to '/wp-json/object-sync-for-salesforce/push/' containing suspicious SQL keywords (e.g., SLEEP, UNION, SELECT).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-15T04:16:47Z","date_published":"2026-08-15T04:16:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-15162/","summary":"An unauthenticated SQL injection vulnerability in the Object Sync for Salesforce WordPress plugin allows remote attackers to execute arbitrary SQL queries via the REST API.","title":"CVE-2026-15162: Unauthenticated SQL Injection in Object Sync for Salesforce Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-15162/"}],"language":"en","title":"CraftedSignal Threat Feed - Object Sync for Salesforce","version":"https://jsonfeed.org/version/1.1"}