Back to Feed
VulnerabilitiesMar 13, 2026

SQL Injection Vulnerability in Ally WordPress Plugin Exposes 200K+ Sites

A SQL injection vulnerability in the Ally WordPress plugin exposes over 200,000 websites to potential data theft and unauthorized access. Although a patch has been released, the majority of affected installations remain unpatched and vulnerable to exploitation.

Summary

A SQL injection vulnerability in the Ally WordPress plugin exposes over 200,000 websites to potential data theft and unauthorized access. Although a patch has been released, the majority of affected installations remain unpatched and vulnerable to exploitation.