HIGH
minnpost
CVE published 2026-08-15
CVE-2026-15162
The Object Sync for Salesforce plugin for WordPress is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. This allows unauthenticated attackers to append additional SQL queries, enabling extraction of sensitive information such as password hashes from the database.