Junglewise Threat Intelligence

CVE-2026-39581: WP Sessions Time Monitoring Full Automatic SQL injection

CVE-2026-39581 · Severity: high · CVSS 8.5 · Published 2026-06-16

Executive brief

A security vulnerability exists in the WP Sessions Time Monitoring Full Automatic plugin for WordPress, which is used to track user activity on websites. An attacker with a basic 'Subscriber' account can exploit this flaw to access or manipulate the website's database. This could lead to the theft of sensitive customer information or disruption of site operations.

Technical details

The WP Sessions Time Monitoring Full Automatic plugin for WordPress contains a SQL injection vulnerability due to improper neutralization of special elements in SQL commands (CWE-89). The flaw exists in versions up to and including 1.1.4. An authenticated attacker with Subscriber-level permissions or higher can send specially crafted network requests to execute arbitrary SQL queries against the database. This can result in unauthorized data retrieval, including sensitive user information, or limited impact on database availability. The issue is resolved in version 1.1.5.

Affected products

  • WP Sessions Time Monitoring Full Automatic WP Sessions Time Monitoring Full Automatic <= 1.1.4

Timeline

  • 2026-02-20: other: Reported by hivesec
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-06-16: disclosed: NVD publication date

References