VYPR
Unrated severityNVD Advisory· Published Aug 3, 2026· Updated Aug 3, 2026

LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie

CVE-2026-16572

Description

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks on any page that renders one of the LogMyTrip WordPress plugin through 1.9's shortcodes.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.