CVE-2026-4079

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:guaven:sql_chart_builder:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2026-04-07 07:16

Updated : 2026-06-17 10:55


NVD link : CVE-2026-4079

Mitre link : CVE-2026-4079

CVE.ORG link : CVE-2026-4079


JSON object : View

Products Affected

guaven

  • sql_chart_builder
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')