Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106097— Code Snippets < 3.10.0 - Admin+ SQLi in Migration Importers Leading to Network-Wide Credential Disclosure (Multisite)

Quick assessment

Affected
Unknown Code Snippets
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Code Snippets WordPress 插件 3.10.0 版本之前,其在部分用于代码片段迁移导入的端点中,未对用户提供的参数进行 sanitization(清理)和 escaping(转义),便直接将其用于 SQL 查询。这些端点对所有具备站点管理权限的用户均可访问;在 WordPress 多站点网络中,这类权限属于子站点管理员。因此,非网络超级管理员的子站点管理员可利用基于 UNION 的 SQL 注入攻击共享的网络数据库表,从而泄露全网范围内的数据,例如其他用户的密码哈希值。

AI Predicted 8.8 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106097

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Code Snippets < 3.10.0 - Admin+ SQLi in Migration Importers Leading to Network-Wide Credential Disclosure (Multisite)
Source: CVE Program / CVE List V5
Vulnerability Description
The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabilities; on a WordPress Multisite network those belong to subsite Administrators, allowing a subsite Administrator who is not a network Super Admin to perform UNION-based SQL injection against shared network tables and disclose network-wide data such as other users' password hashes.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Code Snippets 0 ~ 3.10.0 -

II. Public POCs for CVE-2026-106097

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106097

请登录查看更多情报信息。

Other References for CVE-2026-106097 (1)

Same Patch Batch · Unknown · 2026-10-09 · 16 CVEs total

CVE-2026-89235 6.8 MEDIUM Testimonials by BestWebSoft 1.0.5 - 1.0.8 - Unauthenticated SQLi via 'offset' Parameter
CVE-2026-86851 6.5 MEDIUM Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection &
CVE-2026-103329 5.3 MEDIUM Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signatu
CVE-2026-87846 5.3 MEDIUM Shipping for Nova Poshta 1.18.7 - 1.19.8 - Unauthenticated Order Shipment Record Deletion
CVE-2026-84220 4.8 MEDIUM Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection
CVE-2026-85348 4.3 MEDIUM GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF
CVE-2026-84224 4.1 MEDIUM Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL
CVE-2026-106095 Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via upd
CVE-2026-93548 FooSales < 1.43.3 - Subscriber+ Privilege Escalation via User Impersonation
CVE-2026-87841 UnitechPay <= 1.0.6.3 - Unauthenticated Order Payment Bypass via Unsigned Webhook
CVE-2026-92990 SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded T
CVE-2026-88931 Social Web Suite <= 4.1.12 - Unauthenticated Arbitrary Plugin Settings Update
CVE-2026-86850 SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deleti
CVE-2025-15700 AWP Classifieds < 4.4.9 - Admin+ Arbitrary File Upload via ZIP Import
CVE-2026-92989 SendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter Queueing

IV. Related Vulnerabilities

V. Comments for CVE-2026-106097

No comments yet


Leave a comment