Junglewise Threat Intelligence

CVE-2026-54819: Webilia Listdom Blind SQL Injection

CVE-2026-54819 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Executive brief

Webilia Listdom, a WordPress plugin used for creating directory and listing websites, contains a critical security flaw. This vulnerability allows an attacker to interact directly with the website's database without needing a password. An exploit could lead to the theft of sensitive customer data or internal site information, potentially impacting the organization's reputation and data privacy compliance.

Technical details

A Blind SQL Injection vulnerability exists in the Webilia Inc. Listdom plugin for WordPress (versions up to and including 5.4.0) due to improper neutralization of special elements in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary SQL queries against the backend database. Because it is a 'blind' injection, attackers can infer data by observing differences in application responses or timing. This can lead to full database extraction. The issue is resolved in version 5.5.0.

Affected products

  • Webilia Inc. Listdom n/a through 5.4.0

Timeline

  • 2026-04-24: other: Vulnerability reported by researcher Evan NR
  • 2026-06-17: advisory: Advisory published by Patchstack and NVD
  • 2026-06-17: patched: Patch released in version 5.5.0

References