WordPress security by component
Software Issue Manager
Plugin description
Software Issue Manager is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 8.6.
Plugin slug:
software-issue-managerLatest vulnerability
CVE-2026-12877: Software Issue Manager exposes front-end search SQL injection
Software Issue Manager before 5.1.0 rewrites the standard front-end WordPress search query when author limiting and a guest-submitted issue are present. The unauthenticated s parameter is concatenated into the generated SQL without sanitization or escaping, allowing attacker-controlled SQL such as a time-delay expression to reach the database.
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-12877
Software Issue Manager exposes front-end search SQL injection
Software Issue Manager before 5.1.0 rewrites the standard front-end WordPress search query when author limiting and a guest-submitted issue are present. The unauthenticated s parameter is concatenated into the generated SQL without sanitization or escaping, allowing attacker-controlled SQL such as a time-delay expression to reach the database.
|
5.1.0 |
CVE8.6
NVDPending
|
| Aug 12, 2025 |
CVE-2025-8314
Software Issue Manager: Cross-site scripting
Software Issue Manager is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|