WordPress security by component
logmytrip
logmytrip (logmytrip) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 8.6.
Plugin slug:
logmytripLatest vulnerability
CVE-2026-16572: LogMyTrip shortcode pages expose an unauthenticated SQL injection
LogMyTrip through 1.9 reads an attacker-controlled cookie value and uses it in a SQL query without sanitization or escaping. Any unauthenticated visitor can supply a malicious cookie to a page rendering one of the plugin's shortcodes and alter the resulting database query. The CNA record does not disclose the cookie name, shortcode, query, vulnerable function or obtainable database fields.
| Safe version |
|
||
|---|---|---|---|
| Aug 03, 2026 |
CVE-2026-16572
LogMyTrip shortcode pages expose an unauthenticated SQL injection
LogMyTrip through 1.9 reads an attacker-controlled cookie value and uses it in a SQL query without sanitization or escaping. Any unauthenticated visitor can supply a malicious cookie to a page rendering one of the plugin's shortcodes and alter the resulting database query. The CNA record does not disclose the cookie name, shortcode, query, vulnerable function or obtainable database fields.
|
> 1.9 |
CVE8.6
NVDPending
|