Junglewise Threat Intelligence

CVE-2026-16949: Term Pages SQL injection via tp_lookup

CVE-2026-16949 · Severity: medium · CVSS 5.8 · Published 2026-08-10

Executive brief

Term Pages is a WordPress plugin for managing custom term-based content pages. The plugin contains an unauthenticated SQL injection vulnerability in its wp-admin AJAX handler that allows attackers to query and extract sensitive database information without authentication or special configuration.

Technical details

The vulnerability is a SQL injection (CWE-89) in the tp_lookup AJAX action handler. The plugin fails to properly sanitize and escape a user-supplied parameter (q) before incorporating it into a SQL query. An unauthenticated attacker can exploit this via a network request to wp-admin/admin-ajax.php without authentication, nonce validation, or special configuration required. Attacks can extract database metadata using time-based blind SQL injection techniques. The vulnerability was fixed in version 2.0.0.

Affected products

  • Term Pages Term Pages before 2.0.0

Timeline

  • 2026-08-06: disclosed
  • 2026-08-10: patched: Fixed in version 2.0.0

References