Junglewise Threat Intelligence

CVE-2026-57787: CreativeWS CWS SVGicons SQL injection

CVE-2026-57787 · Severity: high · CVSS 8.5 · Published 2026-07-13

Executive brief

CreativeWS CWS SVGicons, a WordPress plugin used for managing SVG icons, contains a security vulnerability that could allow an attacker to access sensitive information from the website's database. By exploiting this flaw, a user with basic contributor-level access could bypass security controls to extract data they are not authorized to see. This could lead to the exposure of customer information, site configuration details, or other private data stored in the database.

Technical details

A Blind SQL Injection vulnerability exists in the CreativeWS CWS SVGicons plugin (cws-svgicons) for WordPress in versions up to 1.5.5. The flaw stems from the improper neutralization of user-supplied input used within SQL queries. An attacker with Contributor-level privileges can exploit this via network requests to interact directly with the underlying database. Successful exploitation allows for the extraction of sensitive information through inference-based techniques (Blind SQLi). As of the advisory date, no official patch has been released.

Affected products

  • CreativeWS CWS SVGicons <= 1.5.5

Timeline

  • 2026-01-20: disclosed: Reported by Phat RiO
  • 2026-07-13: advisory: NVD publication date

References