Executive brief
The Database Collation Fix plugin for WordPress, which helps manage database character sets, is vulnerable to a security flaw that could allow attackers to steal sensitive information. By exploiting a weakness in how the plugin handles specific settings, an attacker can run unauthorized database queries. However, this attack is difficult to perform because it requires a specific temporary file to be present on the server, typically created only during site maintenance tasks like migrations or exports.
Technical details
The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL injection due to insufficient escaping of the 'force-collation-algorithm' parameter and a lack of SQL query preparation. An attacker can exploit this to append malicious SQL queries and extract sensitive data from the database. The vulnerability has a high complexity (AC:H) because exploitation requires a specific 'trigger.txt' file to exist in the plugin's directory. This file is typically only generated during DesktopServer integration events such as site creation, copying, importing, or deployment. The issue is addressed in versions following 1.2.10.
Affected products
- davejesch Database Collation Fix <= 1.2.10
Timeline
- 2026-08-01: disclosed
- 2026-08-01: advisory
References
- https://plugins.trac.wordpress.org/browser/database-collation-fix/trunk/databasecollationfix.php
- https://plugins.trac.wordpress.org/browser/database-collation-fix/trunk/databasecollationfix.php
- https://plugins.trac.wordpress.org/browser/database-collation-fix/trunk/databasecollationfix.php
- https://plugins.trac.wordpress.org/browser/database-collation-fix/trunk/databasecollationfix.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3602218%40database-collation-fix&new=3602218%40database-collation-fix
- https://www.wordfence.com/threat-intel/vulnerabilities/id/874c1ba5-1bbd-43ac-bc5c-901638fa56ef?source=cve