CVE-2026-96331: Wpdreams AJAX Search Pro

Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdreams Ajax Search Pro ajax-search-pro allows Blind SQL Injection.This issue affects Ajax Search Pro: from n/a through 4.29.1.

Affected products

  • Wpdreams AJAX Search Pro: up to and including 4.29.1

Published 2026-10-09. Last modified 2026-10-09.