MEDIUM
afthemes
CVE published 2026-08-05
CVE-2026-11977
The WP Post Author plugin for WordPress has a SQL Injection vulnerability via the 'wpma_metabox_authors_list' parameter in versions up to 3.9.1. This allows authenticated attackers with author-level access to inject SQL queries and extract sensitive information from the database. The vulnerability requires a two-step process: saving a crafted guest-author token and triggering the injection on the post lis [truncated]