Executive brief
WPMasterToolKit is a WordPress plugin providing site management and optimization tools. A SQL injection vulnerability in the plugin allows authenticated administrators to execute arbitrary SQL queries against the WordPress database, potentially exposing, modifying, or deleting sensitive data including user accounts and private customer information.
Technical details
The vulnerability is a SQL injection (SQLi) flaw in WPMasterToolKit versions up to 2.22.0 that requires administrator-level privileges to exploit. The root cause stems from insufficient input sanitization or parameterization in a database query within the plugin's code. An authenticated administrator can craft a malicious request to inject arbitrary SQL commands, allowing them to read, modify, or delete database contents. The vulnerability has been patched in version 2.23.1. No evidence of active exploitation in the wild has been reported.
Affected products
- Webdeclic WPMasterToolKit up to 2.22.0
Timeline
- 2026-09-17: disclosed: Published by Patchstack
- 2026-09-17: patched: Fixed in version 2.23.1