CVE-2026-2831Disclosure

MEDIUMCVSS 4.9 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-27); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-27: 2Mentions · 2026-06-08: 1Active Exploitation · 2026-06-08: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-02-27: 2Technical Details · 2026-06-08: 102-2706-08
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure2
2026-06-081
Active Exploitation1
Full discourse3 posts
  • Cert-IST@cert_ist
    Active Exploitation

    La CISA a signalée Vendredi des attaques ciblant la CVE-2026-2831, une vulnérabilité dans SolarWinds Serv-U qui a été corrigée deux jours plus tôt. Elle peut donner lieu à un déni de service (DoS) via des requêtes POST spécialement conçues. https://tinyurl.com/397rbttv

    Post summary

    CISA reported ongoing attacks exploiting SolarWinds Serv-U CVE-2026-2831, a DoS vulnerability that had just been patched.

    0000083
    957 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2831 The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, and including, 4.5.0 due to insufficient escaping … https://www.cve.org/CVERecord?id=CVE-2026-2831

    Post summary

    CVE-2026-2831 is an SQL injection vulnerability in the MailArchiver WordPress plugin's logid parameter affecting all versions up to 4.5.0 due to insufficient escaping.

    0000068
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2831 SQL Injection in WordPress MailArchiver Plugin Versions 4.5.0 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2831

    Post summary

    The post announces a SQL injection vulnerability (CVE‑2026‑2831) in WordPress MailArchiver Plugin versions 4.5.0 and earlier.

    0000024
    4.0K followersView on X

Explore more