CVE-2026-82304: Unknown Music Store
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Affected products
- Unknown Music Store: from 1.0.245, before 1.4.5 (fixed in 1.4.5)
Published 2026-09-05. Last modified 2026-09-08.