VYPR

Object Sync for Salesforce

by WordPress

CVEs (1)

  • CVE-2026-15162HigAug 15, 2026
    risk 0.49cvss 7.5epss

    The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push…