CVE-2026-11977
medium
📛 Threat Title
WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection
Description
The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation is a two-step chain: an attacker first saves a crafted guest-author token via the wpma_metabox_authors_list parameter during post creation or editing, then triggers the injection when any admin user loads the post list screen at /wp-admin/edit.php, causing the injected SQL result to be rendered in the Authors column. Affected software — plugin: WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars (affected: *-3.9.1). CVSS 6.5 (Medium) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2026-11977
IOC database
- Type
- cve
- Value
CVE-2026-11977- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
Remediations (9)
-
web:cybernews.com
Microsoft's July 2026 Patch Tuesday fixes a record 622 vulnerabilities and begins mandatory Kerberos RC4 enforcement, marking one of Windows' biggest security updates.
-
web:nvd.nist.gov
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:support.sap.com
SAP security Patch Day Bulletin This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape. On 9th of June 2026 , SAP security patch day saw the release of 15 new security notes.
-
web:techcommunity.microsoft.com
Hi team, Our organization has successfully implemented the recommended mitigation for CVE - 2026 -42897. However, we are currently experiencing the documented known issues within our environment. Could the Exchange team kindly provide a tentative timeline or ETA for a permanent security update that resolves the underlying vulnerability while addressing these known issues? We would greatly ...
-
web:techcommunity.microsoft.com
Are those solved in the CVE - 2026 -42897 fix (June 2026 SU)? Yes, when June 2026 SU is installed and mitigation is removed, known issues should be resolved too. But note that mitigations do not get removed automatically after installation of the SU (and we recommend that you keep then enabled for a little while longer).
-
web:www.malwarebytes.com
This Chrome update fixes critical flaws attackers could exploit through malicious websites, but not the "Browser Fetch" vulnerability.
-
web:www.nist.gov
NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.
-
Wordfence remediation: WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom AvatarsWordfence
Update to version 3.10.0, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.