CVE-2026-4079Disclosure(guaven / sql_chart_builder)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sql_chart_builder

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
sql_chart_builder

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-19: 2Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-20: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-19: 204-0704-1904-20
Signal classification3 categories
Disclosure
360.0%
General
120.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure1General1
2026-04-192
Disclosure2
2026-04-201
PoC1
Full discourse5 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4079-sql-chart-builder-version-2-3-8-high-vulnerability-proof-of-concept CVE-2026-4079 #WordPress plugin #vulnerability sql-chart-builder #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The tweet links to a proof‑of‑concept for CVE-2026-4079, a high‑severity vulnerability in the WordPress plugin sql‑chart‑builder 2.3.8, with no additional technical details or exploitation context provided.

    0000050
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4079 The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct … https://www.cve.org/CVERecord?id=CVE-2026-4079 ----- Traducción: CVE-2026-4079 El … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-4079, a SQL injection flaw in SQL Chart Builder WordPress plugin versions prior to 2.3.8, but offers no PoC, exploit, patch, or exploitation evidence.

    0000046
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4079 The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct … https://www.cve.org/CVERecord?id=CVE-2026-4079

    Post summary

    CVE-2026-4079 reveals a SQL injection vulnerability in the SQL Chart Builder WordPress plugin (pre‑2.3.8) due to unsanitized input concatenation, but no PoC, exploit code, or patch details are disclosed.

    00000220
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4079 SQL Injection in SQL Chart Builder WordPress Plugin Before 2.3.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4079

    Post summary

    This text discloses a SQL injection vulnerability in the SQL Chart Builder WordPress plugin prior to version 2.3.8, without providing PoC, exploit code, or patch details.

    0000046
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4079 - SQL Chart Builder < 2.3.8 - Unauthenticated SQL Injection Intel Report: https://ift.tt/Wk02Bf9

    Post summary

    An alert for CVE-2026-4079 highlighting an unauthenticated SQL injection in SQL Chart Builder versions below 2.3.8, with a link to an intel report but no evidence of exploitation or mitigation.

    0000034
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appguavensql_chart_builder-wordpress-

Explore more