Junglewise Threat Intelligence

CVE-2026-32471: ProLancer Element SQL injection in subscriber endpoint

CVE-2026-32471 · Severity: high · CVSS 8.5 · Published 2026-08-24

Executive brief

ProLancer Element is a WordPress plugin that provides freelancer marketplace functionality. A SQL injection vulnerability in the subscriber endpoint allows authenticated subscribers to read, modify, or delete the entire website database, including user accounts and sensitive data. No official patch has been released as of August 2026.

Technical details

The vulnerability is a SQL injection flaw in the ProLancer Element WordPress plugin versions 1.4.8 and earlier. The vulnerability requires subscriber-level authentication to exploit, making it accessible to low-privilege users or those who can create a subscriber account. An attacker with subscriber privileges can inject malicious SQL queries to read, modify, or delete data from the underlying database. The attack vector is network-based and requires authentication; exploitation does not require user interaction. No official patch was available as of the publication date (24 August 2026).

Affected products

  • ProLancer ProLancer Element <= 1.4.8

Timeline

  • 2026-08-24: disclosed: Published by Patchstack
  • 2026-07-11: other: Reported by Jamaal ahmed

References