Executive brief
iNET Webkit, a WordPress plugin, contains a security flaw that could allow an authorized user with 'Contributor' level access to interact directly with the website's database. An attacker could exploit this to steal sensitive information or disrupt site operations. There is currently no official patch available for this version.
Technical details
A SQL injection vulnerability exists in the iNET Webkit plugin for WordPress, specifically in version 1.2.4. The flaw is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). An attacker with Contributor-level authentication can exploit this via the network without user interaction to perform unauthorized database reads or cause limited availability issues. As of the advisory date, no official patch has been released, and the vulnerability remains unpatched in the affected version.
Affected products
- iNET iNET Webkit 1.2.4
Timeline
- 2026-04-28: disclosed: Reported by Evan NR
- 2026-07-02: advisory: Published by Patchstack and NVD