Junglewise Threat Intelligence

CVE-2026-57643: AF themes WP Post Author SQL injection

CVE-2026-57643 · Severity: high · CVSS 8.5 · Published 2026-06-26

Executive brief

WP Post Author is a WordPress plugin used to display author profiles and bios on website posts. A security vulnerability allows users with 'Contributor' level access to perform unauthorized database queries. This could lead to the theft of sensitive site information or disruption of database operations.

Technical details

The WP Post Author plugin for WordPress contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL command (CWE-89). An attacker with Contributor-level privileges or higher can exploit this flaw via network requests to execute arbitrary SQL queries against the backend database. This can result in the extraction of sensitive data or limited impact on database availability. The issue is resolved in version 3.10.0.

Affected products

  • AF themes WP Post Author <= 3.9.1

Timeline

  • 2026-05-20: other: Reported by researcher hhhai
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Patch released in version 3.10.0

References