A HIGH-severity vulnerability identified as CVE-2026-2993 has been published on May 12, 2026 with a CVSS base score of 7.5. This security advisory provides a detailed breakdown of the vulnerability, its potential impact, weakness classification, and actionable steps to protect your systems.
Table of Contents
ToggleVulnerability Details
CVE ID: CVE-2026-2993
Severity: HIGH
CVSS Score: 7.5
Published: May 12, 2026
Weakness (CWE): CWE-89
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Confidentiality Impact | High |
| Integrity Impact | None |
| Availability Impact | None |
Technical Description
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query in the getListForTbl() function. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: This issue is partially mitigated by a patch in version 1.4.11 that adds a nonce check for a nonce that is only available to administrators.
Potential Impact
If exploited, this high-severity vulnerability could allow an attacker to compromise sensitive data confidentiality. Organizations running affected software should treat this as a priority remediation item.
Recommended Action
No official patch is available yet. Until one is released:
- Monitor the official NVD page and vendor channels for patch announcements.
- Restrict access to the affected system or service where possible.
- Apply network-level mitigations such as firewall rules or WAF policies.
- Enable logging and alerting for anomalous activity related to this vulnerability.
- Review your incident response plan in case of active exploitation.
References
Related Security Advisories
- [HIGH] CVE-2026-3359 — CVSS 7.5 (May 5, 2026) — HIGH / CVSS 7.5
- [CRITICAL] CVE-2026-3325 — CVSS 10.0 (April 29, 2026) — CRITICAL / CVSS 10.0
- [HIGH] CVE-2026-43500 — CVSS 7.8 (May 11, 2026) — HIGH / CVSS 7.8

![[HIGH] CVE-2026-10721 — CVSS 8.4 (June 10, 2026)](https://atlas-cybersecurity.com/wp-content/plugins/elementor/assets/images/placeholder.png)



