All verified exploits

CVE-2026-3658 Unauthenticated SQL Injection via REST API Fields Parameter

Deterministic high WordPress Added cve-verified-cve-2026-3658

Detects WordPress installs running the Simply Schedule Appointments plugin at version 1.6.10.0 or earlier. The plugin's TD_DB_Model::db_query() method takes the fields[] parameter from REST API requests and interpolates values directly into the SQL SELECT clause via backtick-wrapped implode() without sanitization or allowlist validation. An unauthenticated attacker can inject SQL to extract usernames, email addresses, and password hashes from the WordPress database.

Related WordPress exploits

Is your app exploitable through CVE-2026-3658?

Scan your domain free