Executive brief
The nicen-localize-image plugin for WordPress is vulnerable to a security flaw that allows users with 'Contributor' level access to perform unauthorized database queries. This could lead to the theft of sensitive information from the website's database or a partial disruption of service. While the technical severity is high, the risk is somewhat mitigated by the requirement for a valid user account on the site.
Technical details
A SQL injection vulnerability exists in the nicen-localize-image plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 1.4.9. An attacker with Contributor-level privileges or higher can exploit this vulnerability via network requests to execute arbitrary SQL queries against the backend database. This can result in the unauthorized retrieval of sensitive information (Confidentiality: High) and potential impact on database availability. As of the advisory date, no official patch has been released.
Affected products
- 友人a丶 nicen-localize-image <= 1.4.9
Timeline
- 2026-05-23: other: Vulnerability reported by researcher Aurélien BOURDOIS (Elymaro)
- 2026-06-27: advisory: Published by Patchstack
- 2026-07-02: disclosed: NVD publication date