Ally WordPress Plugin Vulnerability Puts Over 200,000 Websites at Risk of SQL Injection Attacks
Trendline Trendline

Ally WordPress Plugin Vulnerability Puts Over 200,000 Websites at Risk of SQL Injection Attacks

What's Happening? A significant security flaw has been identified in the Ally WordPress plugin, which is used to enhance website accessibility features. The vulnerability, tracked as CVE-2026-2413, is an SQL injection issue that arises from insufficient sanitization of user-supplied URL parameters.
Summarized by AI
AI Generated
This may include content generated using AI tools. Glance teams are making active and commercially reasonable efforts to moderate all AI generated content. Glance moderation processes are improving however our processes are carried out on a best-effort basis and may not be exhaustive in nature. Glance encourage our users to consume the content judiciously and rely on their own research for accuracy of facts. Glance maintains that all AI generated content here is for entertainment purposes only.