CVE-2026-9179 | hancock11 WP Forms Connector Plugin up to 1.8 on WordPress REST Endpoint /wp-json/wp/v3/post/list listPost order sql injection
A vulnerability categorized as critical has been discovered in hancock11 WP Forms Connector Plugin up to 1.8 on WordPress. Affected by this vulnerability is the function listPost of the file /wp-json/wp/v3/post/list of the component REST Endpoint. The manipulation of the argument order results in sql injection.
This vulnerability is cataloged as CVE-2026-9179. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More