Apocalypse Meow - Authenticated (Administrator+) SQL Injection via 'type' Parameter vulnerability
high
Authenticated (Administrator+) SQL Injection via 'type' Parameter vulnerability
- CVSS:
- 7.6
- Affected:
- up to 22.1.0
- Fixed in:
- 23.0.0
- Disclosed:
- Mar 4, 2026
Apocalypse Meow <= 22.1.0 - Authenticated (Administrator+) SQL Injection via 'type' Parameter
medium
The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 22.1.0. This is due to a flawed logical operator in the type validation check on line 261 of ajax.php — the condition uses `&&` (AND) instead of `||` (OR), causing the `in_array()` vali...
- CVSS:
- 4.9
- Affected:
- up to 22.1.0
- Fixed in:
- 23.0.0
- Disclosed:
- Mar 4, 2026
CVE-2026-3523 on NVD →
Apocalypse Meow 21.1.3 - 21.2.7 - Authentication Bypass
critical
The Apocalypse Meow plugin for WordPress is vulnerable to Authentication Bypass in versions 21.1.3 - 21.2.7. This is due to improper validation via bcrypt. This makes it possible for unauthenticated attackers to bypass the authentication check.
- CVSS:
- 9.8
- Affected:
- 21.1.3 – 21.2.7
- Fixed in:
- 21.2.8
- Disclosed:
- Dec 3, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database