Vendor
high
advisory
WordPress PickPlugins Question Answer Plugin SQL Injection Vulnerability (CVE-2026-10207)
1 rule 2 TTPs 1 CVEAn unauthenticated SQL injection vulnerability, tracked as CVE-2026-10207, exists in the PickPlugins Question Answer plugin for WordPress versions up to and including 1.2.73, allowing attackers to extract sensitive database information due to insufficient input sanitization of the 'id' GET parameter and improper SQL query construction.
Question Answer plugin <= 1.2.73
wordpress
sql-injection
vulnerability
web-application
1r
2t
1c
critical
threat
WordPress User Verification Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEThe User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in versions up to 2.0.46 due to a loose PHP comparison, allowing unauthenticated attackers to log in as any verified user by submitting a 'true' OTP value.
User Verification by PickPlugins plugin for WordPress <= 2.0.46
wordpress
authentication bypass
cve-2026-7458
2r
1t
1c