Junglewise Threat Intelligence

CVE-2026-66630: PublishPress Series SQL Injection in administrator panel

CVE-2026-66630 · Severity: high · CVSS 7.6 · Published 2026-09-17

Technologies: PublishPress Series. Vendors: PublishPress.

Executive brief

PublishPress Series is a WordPress plugin used to organize and manage content series. An administrator-level SQL injection vulnerability allows authenticated admins to read, modify, or delete the entire database including user accounts and sensitive data, potentially compromising the entire WordPress installation.

Technical details

PublishPress Series plugin versions 3.1.3 and earlier contain an SQL injection vulnerability in the administrator panel. The flaw is rooted in improper input validation/parameterization of database queries. Attack requires administrator privileges to trigger, limiting the attack surface to authenticated admin users. A successful exploit allows complete database access including reading sensitive data, modifying records, or deleting content. The vulnerability is patched in version 3.1.4 and later.

Affected products

  • PublishPress Series <=3.1.3

Timeline

  • 2026-09-17: disclosed: Published by Patchstack
  • 2026-09-17: patched: Version 3.1.4 released

References

Related threats