CVE-2026-108125

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This issue affects wp-post-author version 4.0.0 prior to 4.1.0.

Published 2026-10-09. Last modified 2026-10-09.