Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection
highThe Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push class — no capability or nonce — so it is rea...
- CVSS:
- 7.5
- Affected:
- up to 2.2.13
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2026