CVE-2026-94298 PUBLISHED

BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter

Assigner: WPScan
Reserved: 21.09.2026 Published: 02.10.2026 Updated: 02.10.2026

The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.

Product Status

Vendor Unknown
Product BuildKit
Versions Default: unaffected
  • affected from 0 to 1.0.29 (excl.)

Credits

  • Naiches finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE