All verified exploits

CVE-2026-3334 SQL Injection in CMS Commander Backup Restore

Pentest high WordPress Added cve-verified-cve-2026-3334

Detects WordPress installs running the CMS Commander Client plugin (cms-commander-client) at version 2.288 or earlier. The plugin's restore() function in lib/CMSC/Backup.php uses extract($args) and then interpolates or_blogname, or_blogdescription, and or_admin_email directly into SQL UPDATE queries via PHP string interpolation. Although $wpdb->prepare() is called, the absence of %s placeholders makes it a no-op. An attacker with a valid CMS Commander API key can inject arbitrary SQL via these unsigned parameters, extracting database credentials, user password hashes, and modifying any WordPress configuration.

Related WordPress exploits

Is your app exploitable through CVE-2026-3334?

Scan your domain free