CVE-2026-66624
Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
CVSS
7.6
High
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Sep 17, 2026 · Last modified: Sep 17, 2026 · CWE-89
Not enough EPSS history yet.
Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-929267.3 HIG19.3%
——6A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.1dCVE-2026-666317.6 HIG20.6%
——6Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.1dCVE-2026-666307.6 HIG20.6%
——6Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.1dCVE-2026-666287.6 HIG20.6%
——6Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.1dCVE-2026-666267.6 HIG20.6%
——6Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.1dCVE-2026-666257.6 HIG20.6%
——6Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.1d