Detects WordPress installs running the CMS Commander Client plugin (cms-commander-client) at version 2.288 or earlier. The plugin's restore() function in lib/CMSC/Backup.php uses extract($args) and then interpolates or_blogname, or_blogdescription, and or_admin_email directly into SQL UPDATE queries via PHP string interpolation. Although $wpdb->prepare() is called, the absence of %s placeholders makes it a no-op. An attacker with a valid CMS Commander API key can inject arbitrary SQL via these unsigned parameters, extracting database credentials, user password hashes, and modifying any WordPress configuration.
Is your app exploitable through CVE-2026-3334?
Scan your domain free