PatchDayAlert

CVE

CVE-2026-15162

0field notes · 1digest CVSS 7.5

The verdict

The Object Sync for Salesforce WordPress plugin has an unauthenticated SQL injection bug in its REST API push route. No login, no nonce, no capability check: anyone on the internet can send a crafted request to `/wp-json/object-sync-for-salesforce/push/` and pull password hashes and other sensitive data straight out of your WordPress database. The only prerequisite is knowing a valid post ID (and `1` works). CVSS 7.5, time-based blind injection confirmed.

Patch urgency · Patch within 24 hours


Daily digests