← WordPress Vulnerabilities
WordPress security by component

logmytrip

logmytrip (logmytrip) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 8.6.

Plugin slug: logmytrip

CVE-2026-16572: LogMyTrip shortcode pages expose an unauthenticated SQL injection

LogMyTrip through 1.9 reads an attacker-controlled cookie value and uses it in a SQL query without sanitization or escaping. Any unauthenticated visitor can supply a malicious cookie to a page rendering one of the plugin's shortcodes and alter the resulting database query. The CNA record does not disclose the cookie name, shortcode, query, vulnerable function or obtainable database fields.

PublishedAug 03, 2026
Known safe version> 1.9
Published vulnerabilities for logmytrip
Safe version
Aug 03, 2026 CVE-2026-16572
LogMyTrip shortcode pages expose an unauthenticated SQL injection
LogMyTrip through 1.9 reads an attacker-controlled cookie value and uses it in a SQL query without sanitization or escaping. Any unauthenticated visitor can supply a malicious cookie to a page rendering one of the plugin's shortcodes and alter the resulting database query. The CNA record does not disclose the cookie name, shortcode, query, vulnerable function or obtainable database fields.
> 1.9
CVE8.6
NVDPending