VulnerabilitiesMar 13, 2026
SQL Injection Vulnerability in Ally WordPress Plugin Exposes 200K+ Sites
A SQL injection vulnerability in the Ally WordPress plugin exposes over 200,000 websites to potential data theft and unauthorized access. Although a patch has been released, the majority of affected installations remain unpatched and vulnerable to exploitation.
Summary
A SQL injection vulnerability in the Ally WordPress plugin exposes over 200,000 websites to potential data theft and unauthorized access. Although a patch has been released, the majority of affected installations remain unpatched and vulnerable to exploitation.