PT-2026-23132 · WordPress · Apocalypse Meow
Louis Deschanel
·
Published
2026-03-05
·
Updated
2026-03-08
·
CVE-2026-3523
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apocalypse Meow plugin for WordPress versions prior to 22.1.0
Description
The software is susceptible to SQL injection through the
type parameter. A flawed logical operator in the type validation check allows attacker-controlled single quotes to pass unescaped into SQL queries. This enables authenticated attackers with Administrator-level access or higher to append additional SQL queries, potentially extracting sensitive information from the database. The issue stems from an incorrect use of the '&&' (AND) operator instead of '||' (OR) in the validation process, causing the in array() validation to be bypassed. The stripslashes deep() function further contributes to the issue by removing wp magic quotes() protection.Recommendations
Update the Apocalypse Meow plugin to version 22.1.0 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apocalypse Meow