Executive brief
PublishPress Series is a WordPress plugin used to organize and manage content series. An administrator-level SQL injection vulnerability allows authenticated admins to read, modify, or delete the entire database including user accounts and sensitive data, potentially compromising the entire WordPress installation.
Technical details
PublishPress Series plugin versions 3.1.3 and earlier contain an SQL injection vulnerability in the administrator panel. The flaw is rooted in improper input validation/parameterization of database queries. Attack requires administrator privileges to trigger, limiting the attack surface to authenticated admin users. A successful exploit allows complete database access including reading sensitive data, modifying records, or deleting content. The vulnerability is patched in version 3.1.4 and later.
Affected products
- PublishPress Series <=3.1.3
Timeline
- 2026-09-17: disclosed: Published by Patchstack
- 2026-09-17: patched: Version 3.1.4 released