CVE-2026-3334Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries in the restore workflow. This makes it possible for authenticated attackers, with CMS Commander API key access, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-21); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-21: 3Mentions · 2026-03-22: 1Technical Details · 2026-03-21: 303-2103-22
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-213
Disclosure3
2026-03-221
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3334 The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to… https://www.cve.org/CVERecord?id=CVE-2026-3334

    Post summary

    The CVE‑2026‑3334 concerns an SQL Injection vulnerability in the CMS Commander WordPress plugin via specific parameters, with details available in the CVE record.

    0001084
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3334 - thoefter - CMS Commander – Manage Multiple Sites - https://www.redpacketsecurity.com/cve-alert-cve-2026-3334-thoefter-cms-commander-manage-multiple-sites/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3334 #thoefter #cms-commander-manage-multiple-sites

    Post summary

    The post serves as a straightforward CVE alert, announcing disclosure of CVE‑2026‑3334 affecting the CMS Commander "Manage Multiple Sites" plugin.

    0000063
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3334 - High The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. ... https://www.thehackerwire.com/vulnerability/CVE-2026-3334/ https://t.co/iPdOpNsnpv

    Post summary

    The tweet announces a high severity SQL injection vulnerability (CVE-2026-3334) in the CMS Commander WordPress plugin, detailing the affected parameters and versions, and links to a vulnerability page for more information.

    0000030
    142 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3334: HIGH] WordPress CMS Commander plugin versions up to 2.288 vulnerable to SQL Injection via 'or_blogname', 'or_blogdescription', 'or_admin_email' parameters due to insufficient escaping. Attacker...#cve,CVE-2026-3334,#cybersecurity https://cvefind.com/CVE-2026-3334

    Post summary

    A new SQL injection vulnerability (CVE-2026-3334) in WordPress CMS Commander plugin up to version 2.288 is disclosed, detailing the vulnerable parameters with insufficient escaping.

    0000034
    604 followersView on X

Explore more