Junglewise Threat Intelligence

CVE-2026-54822: SALESmanago & Leadoo SQL injection in WordPress plugin

CVE-2026-54822 · Severity: high · CVSS 8.5 · Published 2026-06-25

Executive brief

The SALESmanago & Leadoo plugin for WordPress, which integrates marketing automation and lead generation tools, contains a security flaw that could allow an attacker to access the website's database. By exploiting this vulnerability, a user with basic 'Subscriber' level access could steal sensitive information or disrupt site operations. This type of flaw is often targeted in automated attacks against many websites simultaneously.

Technical details

A SQL injection vulnerability exists in the SALESmanago & Leadoo plugin for WordPress (versions 3.11.2 and below) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to authenticated users with 'Subscriber' privileges, allowing them to execute arbitrary SQL queries against the backend database. This can lead to unauthorized data exfiltration or limited impact on database availability. The vulnerability is addressed in version 3.11.3.

Affected products

  • SALESmanago SALESmanago & Leadoo <= 3.11.2

Timeline

  • 2026-04-24: other: Reported by researcher endy
  • 2026-06-17: advisory: Patchstack advisory published
  • 2026-06-25: disclosed: NVD publication date
  • 2026-06-17: patched: Version 3.11.3 released to address the issue

References

Related threats