MEDIUM
gm_alex
CVE published 2026-08-05
CVE-2026-15281
The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This vulnerability allows authenticated attackers with subscriber-level access and above to append additional SQL queries into existing queries, potentially leading to sensitive information disclosure. Th [truncated]