CVE-2026-82304

Summary

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

Affected Software

VendorProductVersion RangeStatus
UnknownMusic Store1.0.245 < 1.4.5affected

Weaknesses

  • CWE-89 SQL Injection

References