All verified exploits

CVE-2026-2413 Ally Plugin SQL Injection via URL Path

Deterministic high WordPress Added cve-verified-cve-2026-2413

Detects the Ally (pojo-accessibility) WordPress plugin at version 4.0.3 or earlier, where the get_global_remediations() method uses esc_url_raw() to sanitize the current page URL before concatenating it into a SQL JOIN clause. esc_url_raw() does not escape SQL metacharacters, allowing unauthenticated time-based blind SQL injection.

Related WordPress exploits

Is your app exploitable through CVE-2026-2413?

Scan your domain free