{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/question-answer-plugin--1.2.73/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-10207"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Question Answer plugin \u003c= 1.2.73"],"_cs_severities":["high"],"_cs_tags":["wordpress","sql-injection","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["PickPlugins","WordPress"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability, identified as CVE-2026-10207, has been discovered in the PickPlugins Question Answer plugin for WordPress, affecting all versions up to and including 1.2.73. This flaw permits unauthenticated attackers to exploit insufficient sanitization of the 'id' GET parameter within the user profile template. The vulnerability is compounded by the plugin's use of \u003ccode\u003ewp_unslash()\u003c/code\u003e which bypasses WordPress's native magic quotes protection, leading to direct concatenation of user-supplied input into a SQL query within the \u003ccode\u003eqa_user_profile_card()\u003c/code\u003e function without proper escaping or prepared statements. This weakness enables attackers to append arbitrary SQL queries, potentially facilitating the extraction of sensitive information from the underlying database. The vulnerability does not require prior authentication, making it a severe risk for affected WordPress installations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker crafts a malicious HTTP GET request targeting a WordPress site running the vulnerable PickPlugins Question Answer plugin.\u003c/li\u003e\n\u003cli\u003eThe request is directed at a URL associated with the plugin's user profile template, including a specially crafted \u003ccode\u003eid\u003c/code\u003e GET parameter.\u003c/li\u003e\n\u003cli\u003eThe WordPress application receives the request and the PickPlugins Question Answer plugin's \u003ccode\u003eqa_user_profile_card()\u003c/code\u003e function processes the \u003ccode\u003eid\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin utilizes \u003ccode\u003ewp_unslash()\u003c/code\u003e on the user-supplied \u003ccode\u003eid\u003c/code\u003e parameter, inadvertently removing any WordPress-provided magic quotes protection.\u003c/li\u003e\n\u003cli\u003eThe unsanitized and unescaped \u003ccode\u003eid\u003c/code\u003e parameter is then directly concatenated into a SQL query within the plugin's backend code.\u003c/li\u003e\n\u003cli\u003eThe malicious SQL payload embedded in the \u003ccode\u003eid\u003c/code\u003e parameter modifies the original query, allowing the attacker to execute arbitrary SQL commands.\u003c/li\u003e\n\u003cli\u003eThe database executes the attacker's appended SQL queries.\u003c/li\u003e\n\u003cli\u003eSensitive information, such as user data, configuration details, or other database contents, is extracted and returned to the attacker.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-10207 allows unauthenticated attackers to perform SQL injection. The primary impact is the unauthorized disclosure of sensitive data stored in the WordPress database. This could include user credentials (hashed or plaintext), personal information, website configuration details, and other proprietary data, leading to severe privacy breaches, potential account takeover, and further compromise of the WordPress site. While no specific victim counts or targeted sectors are provided, any organization or individual using the vulnerable plugin is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the PickPlugins Question Answer plugin to a version greater than 1.2.73 to patch CVE-2026-10207.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule in this brief to your SIEM to detect attempts to exploit CVE-2026-10207.\u003c/li\u003e\n\u003cli\u003eEnsure web server access logs are collected and sent to your SIEM for analysis, as the rule relies on \u003ccode\u003ewebserver\u003c/code\u003e logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T10:19:05Z","date_published":"2026-07-28T10:19:05Z","id":"https://feed.craftedsignal.io/briefs/2026-07-pickplugins-sql-injection/","summary":"An unauthenticated SQL injection vulnerability, tracked as CVE-2026-10207, exists in the PickPlugins Question Answer plugin for WordPress versions up to and including 1.2.73, allowing attackers to extract sensitive database information due to insufficient input sanitization of the 'id' GET parameter and improper SQL query construction.","title":"WordPress PickPlugins Question Answer Plugin SQL Injection Vulnerability (CVE-2026-10207)","url":"https://feed.craftedsignal.io/briefs/2026-07-pickplugins-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Question Answer Plugin \u003c= 1.2.73","version":"https://jsonfeed.org/version/1.1"}