← WordPress Vulnerabilities
WordPress security by component

Software Issue Manager

Software Issue Manager is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 8.6.

Plugin slug: software-issue-manager

CVE-2026-12877: Software Issue Manager exposes front-end search SQL injection

Software Issue Manager before 5.1.0 rewrites the standard front-end WordPress search query when author limiting and a guest-submitted issue are present. The unauthenticated s parameter is concatenated into the generated SQL without sanitization or escaping, allowing attacker-controlled SQL such as a time-delay expression to reach the database.

PublishedJul 24, 2026
Known safe version5.1.0
Safe version
Jul 24, 2026 CVE-2026-12877
Software Issue Manager exposes front-end search SQL injection
Software Issue Manager before 5.1.0 rewrites the standard front-end WordPress search query when author limiting and a guest-submitted issue are present. The unauthenticated s parameter is concatenated into the generated SQL without sanitization or escaping, allowing attacker-controlled SQL such as a time-delay expression to reach the database.
5.1.0
CVE8.6
NVDPending
Aug 12, 2025 CVE-2025-8314
Software Issue Manager: Cross-site scripting
Software Issue Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending