PatchSiren

LogMyTrip CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review LogMyTrip CVE published 2026-08-03

CVE-2026-16572

The LogMyTrip WordPress plugin through 1.9 is vulnerable to SQL injection attacks due to improper sanitization and escaping of a value taken from a cookie before using it in a SQL query. This allows unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes. The CVE record was published on 2026-08-03T07:16:42.227Z and has [truncated]