Executive brief
SpeakOut! Email Petitions is a WordPress plugin used to create and manage online petitions. A security flaw allows unauthorized individuals to access the website's database without a password. This could lead to the theft of sensitive user information, such as email addresses and petition signatures, or cause disruptions to the website's operations.
Technical details
The SpeakOut! Email Petitions plugin for WordPress is vulnerable to an unauthenticated SQL injection due to improper neutralization of special elements used in an SQL command (CWE-89). This vulnerability exists in versions up to and including 4.6.5. A remote attacker can exploit this flaw by sending specially crafted network requests to the affected site without requiring any login credentials or user interaction. Successful exploitation allows the attacker to directly interact with the underlying database, potentially leading to full data exfiltration or unauthorized modifications. The issue is resolved in version 4.6.5.1.
Affected products
- SpeakOut! SpeakOut! Email Petitions <= 4.6.5
Timeline
- 2026-02-11: other: Reported by Nguyen Ba Khanh
- 2026-04-13: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date