Detects the Ally (pojo-accessibility) WordPress plugin at version 4.0.3 or earlier, where the get_global_remediations() method uses esc_url_raw() to sanitize the current page URL before concatenating it into a SQL JOIN clause. esc_url_raw() does not escape SQL metacharacters, allowing unauthenticated time-based blind SQL injection.
Is your app exploitable through CVE-2026-2413?
Scan your domain free