CVE-2026-4079 PUBLISHED

SQL Chart Builder < 2.3.8 - Unauthenticated SQL Injection

Assigner: WPScan
Reserved: 12.03.2026 Published: 07.04.2026 Updated: 07.04.2026

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

Product Status

Vendor Unknown
Product SQL Chart Builder
Versions Default: unaffected
  • affected from 0 to 2.3.8 (excl.)

Credits

  • dangnosuy finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE