
CVE-2026-2503 The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_post' AJAX action in a… https://www.cve.org/CVERecord?id=CVE-2026-2503
Post summary
A time‑based SQL injection vulnerability was disclosed in the ElementCamp WordPress plugin, affecting the 'meta_query[compare]' parameter in the 'tcg_select2_search_post' AJAX action, with no exploit code, patch, or active exploitation mentioned.
