
CVE-2026-16572 The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to … https://www.cve.org/CVERecord?id=CVE-2026-16572
Post summary
The LogMyTrip WordPress plugin (versions ≤1.9) is vulnerable to unauthenticated SQL injection due to unsanitized cookie values, as described in CVE-2026-16572.

