Home

Description

The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.

PUBLISHED Reserved 2026-03-26 | Published 2026-05-08 | Updated 2026-05-08 | Assigner WPScan

Problem types

CWE-89 SQL Injection

Product status

Default status
unaffected

Any version before 1.1.23
affected

Credits

mcdruid finder

WPScan coordinator

References

wpscan.com/...rability/54bc1bf4-1033-49e2-aff9-a14c834c35bd/ exploit vdb-entry technical-description

cve.org (CVE-2026-4935)

nvd.nist.gov (CVE-2026-4935)

Download JSON