WordPress security by component
CMS Commander
Plugin description
CMS Commander is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Mar 21, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
cms-commander-clientLatest vulnerability
CVE-2026-3334: CMS Commander: SQL injection
CMS Commander is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Mar 21, 2026 |
CVE-2026-3334
CMS Commander: SQL injection
CMS Commander is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jun 20, 2023 |
CVE-2023-3325
CMS Commander: Privilege escalation or authentication bypass
CMS Commander is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.1
NVD9.8
|