Executive brief
Term Pages is a WordPress plugin for managing custom term-based content pages. The plugin contains an unauthenticated SQL injection vulnerability in its wp-admin AJAX handler that allows attackers to query and extract sensitive database information without authentication or special configuration.
Technical details
The vulnerability is a SQL injection (CWE-89) in the tp_lookup AJAX action handler. The plugin fails to properly sanitize and escape a user-supplied parameter (q) before incorporating it into a SQL query. An unauthenticated attacker can exploit this via a network request to wp-admin/admin-ajax.php without authentication, nonce validation, or special configuration required. Attacks can extract database metadata using time-based blind SQL injection techniques. The vulnerability was fixed in version 2.0.0.
Affected products
- Term Pages Term Pages before 2.0.0
Timeline
- 2026-08-06: disclosed
- 2026-08-10: patched: Fixed in version 2.0.0