Junglewise Threat Intelligence

CVE-2026-15304: foomagoo Plugin Organizer SQL injection in perform_plugin_search

CVE-2026-15304 · Severity: medium · CVSS 6.5 · Published 2026-07-28

Executive brief

The Plugin Organizer plugin for WordPress, which allows administrators to manage and reorder how plugins load, contains a security flaw that could allow users with low-level accounts (like subscribers) to access sensitive information. By exploiting a weakness in how the plugin searches for data, an attacker can run unauthorized database queries. This could lead to the exposure of private site data, including user details or configuration settings. The issue has been addressed in version 10.2.5.

Technical details

A SQL injection vulnerability exists in the perform_plugin_search() function of the Plugin Organizer plugin for WordPress. The root cause is insufficient escaping of the 'PO_plugin_path' parameter; specifically, the output of esc_sql() is passed as a replacement string to preg_replace(), which collapses backslash escapes and bypasses quoting protections. Furthermore, the associated AJAX handler lacks proper nonce verification and capability checks. Authenticated attackers with subscriber-level permissions or higher can exploit this to append malicious SQL queries and extract sensitive data. The vulnerability is fixed in version 10.2.5.

Affected products

  • foomagoo Plugin Organizer up to, and including, 10.2.4

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched: Fixed in version 10.2.5

References