VYPR
High severity8.3OSV Advisory· Published Jan 19, 2026· Updated Jun 17, 2026

CVE-2026-22850

CVE-2026-22850

Description

Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL execution through unescaped analytics export/import and permissive admin SQL import. Unauthenticated visitors can submit arbitrary path (pa) and referrer (r) values to the public tracking endpoint in src/Resources/functions/collect.php, which stores those strings verbatim in the analytics tables. The admin export logic in src/Admin/Data_Export.php writes these stored values directly into SQL INSERT statements without escaping. A crafted path such as "),('999','x');DROP TABLE wp_users;-- breaks out of the value list. When an administrator later imports that export file, the import handler in src/Admin/Data_Import.php reads the uploaded SQL with file_get_contents, performs only a superficial header check, splits on semicolons, and executes each statement via $wpdb->query with no validation of table names or statement types. Additionally, any authenticated user with manage_koko_analytics can upload an arbitrary .sql file and have it executed in the same permissive way. Combined, attacker-controlled input flows from the tracking endpoint into exported SQL and through the import execution sink, or directly via malicious uploads, enabling arbitrary SQL execution. In a worst-case scenario, attackers can achieve arbitrary SQL execution on the WordPress database, allowing deletion of core tables (e.g., wp_users), insertion of backdoor administrator accounts, or other destructive/privilege-escalating actions. Version 2.1.3 patches the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • 1.0, 1.0.1, 1.0.10, …+ 2 more
    • (no CPE)range: 1.0, 1.0.1, 1.0.10, …
    • cpe:2.3:a:ibericode:koko_analytics:*:*:*:*:*:wordpress:*:*range: <2.1.3
    • (no CPE)range: <2.1.3
  • WordPress/Koko Analyticsllm-fuzzy2 versions
    <2.1.3+ 1 more
    • (no CPE)range: <2.1.3
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.