Junglewise Threat Intelligence

CVE-2026-15293: WP Business Intelligence Lite authorization bypass in SQL query management

CVE-2026-15293 · Severity: high · CVSS 8 · Published 2026-07-10

Executive brief

The WP Business Intelligence Lite plugin for WordPress, which is used to display data and reports, contains a security flaw that allows low-level users to bypass authorization checks. An attacker with a basic account can modify the database queries used by the plugin. If an administrator later views these modified queries, the attacker could gain full control over the website or access sensitive data.

Technical details

The WP Business Intelligence Lite plugin for WordPress (versions up to 3.2.0) is vulnerable to an authorization bypass due to missing capability checks in the plugin's query management logic. Authenticated attackers with Subscriber-level permissions or higher can exploit this to modify stored SQL queries. When an administrator subsequently views or interacts with these modified queries, it can lead to arbitrary SQL execution and privilege escalation. The vulnerability is tracked as CWE-862 and requires minimal user interaction from an administrator to achieve full impact.

Affected products

  • joeyoungblood WP Business Intelligence Lite up to, and including, 3.2.0

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References