← WordPress Vulnerabilities
WordPress security by component

CMS Commander

CMS Commander is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Mar 21, 2026; the highest published CVSS base score is 8.8.

Plugin slug: cms-commander-client

CVE-2026-3334: CMS Commander: SQL injection

CMS Commander is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedMar 21, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for cms-commander-client
Safe version
Mar 21, 2026 CVE-2026-3334
CMS Commander: SQL injection
CMS Commander is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending
Jun 20, 2023 CVE-2023-3325
CMS Commander: Privilege escalation or authentication bypass
CMS Commander is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.1
NVD9.8