cve.akaoma.com Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)
Article Content
- •CVE-2026-49776 is a critical SQL injection vulnerability in GPTranslate plugin for WordPress.
- •The flaw allows unauthenticated attackers to execute arbitrary SQL queries on affected systems.
- •Users must update to version 2.32.7 or later to mitigate the risk of exploitation.
A critical unauthenticated SQL injection vulnerability (CVE-2026-49776) has been identified in the GPTranslate plugin for WordPress, affecting versions 2.32.6 and earlier. This flaw allows attackers to execute arbitrary SQL queries through user-controlled input, potentially exposing sensitive data such as usernames and password hashes. Currently, there is no evidence of public exploitation or proof-of-concept code. A patch has been released, and users are advised to update to version 2.32.7 or later immediately. If updates cannot be applied, disabling or removing the plugin is recommended. The vulnerability has been assigned a CVSS score of 9.3, indicating its critical nature. Security professionals are urged to implement Web Application Firewall (WAF) rules to mitigate potential SQL injection attempts targeting the plugin.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-49776 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…