CVE-2026-87774 PUBLISHED

Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week

Assigner: WPScan
Reserved: 09.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

Product Status

Vendor Unknown
Product Tz Weekly Radio Schedule
Versions Default: unknown
  • affected from 0 to 1.8.1 (incl.)

Credits

  • Theo Antônio Da Fonseca finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE