Junglewise Threat Intelligence

CVE-2026-54185: Themeco Cornerstone SQL injection in WordPress plugin

CVE-2026-54185 · Severity: high · CVSS 8.5 · Published 2026-06-17

Technologies: THEMECO Cornerstone. Vendors: THEMECO.

Executive brief

Themeco Cornerstone, a popular page builder plugin for WordPress, contains a security vulnerability that allows users with basic 'Subscriber' accounts to perform unauthorized database queries. An attacker could exploit this to steal sensitive information from the website's database, such as user details or configuration data. This could lead to a significant data breach or further compromise of the website's operations.

Technical details

A SQL injection vulnerability (CWE-89) exists in the Themeco Cornerstone plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw is accessible to authenticated users with 'Subscriber' privileges, allowing them to execute arbitrary SQL queries against the backend database. This can lead to unauthorized data exfiltration or partial impact on service availability. The vulnerability is addressed in version 7.8.8.

Affected products

  • Themeco Cornerstone < 7.8.8

Timeline

  • 2026-04-23: other: Vulnerability reported by Nguyen Ba Khanh
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats