Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. | |
| Title | WordPress UDesign Core plugin <= 4.15.0 - SQL Injection vulnerability | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-06T10:31:31.076Z
Reserved: 2026-04-27T10:39:10.016Z
Link: CVE-2026-42416
Updated: 2026-10-06T10:28:57.467Z
Status : Received
Published: 2026-10-06T09:17:54.610
Modified: 2026-10-06T11:17:28.257
Link: CVE-2026-42416
No data.
OpenCVE Enrichment
Updated: 2026-10-06T12:00:15Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')