{"id":"CVE-2026-12983","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-12983","summary":"The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The…","details":"The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.","published":"2026-08-19T06:00:14.031Z","modified":"2026-08-19T06:00:14.031Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://wpscan.com/vulnerability/1369f95a-4ad3-4b0e-a87f-da88d200685e/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T06:00:14.031Z"}}