CVE-2026-12983
HIGH NVDCVSS Score
8.6
Severity
HIGH
Source
NVD
Published
Aug 19, 2026
Description
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.