CVE-2026-56036: WordPress 워드프레스 결제 심플페이 plugin <= 5.5.6 - SQL Injection vulnerability
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
Metrics
- CVSS v3.1
- 9.3
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unauthenticated SQL injection vulnerability affects the WordPress plugin 워드프레스 결제 심플페이 (WordPress Payment SimplePay by codemstory) at version 5.5.6 and earlier. The flaw is reachable over the network with no credentials required, making it exploitable by any party that can send HTTP requests to a WordPress site running the plugin. Successful exploitation gives an attacker read access to the underlying database and causes limited disruption to service availability. No fix version has been published yet; HarborGuard is tracking the advisory and will surface a patched rebuild as soon as upstream ships one.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from Patchstack and other upstream advisory feeds within minutes of publication and matched against customer images, including custom-built WordPress images that bundle this plugin. Any image found to carry an affected version of 워드프레스 결제 심플페이 at or below 5.5.6 is flagged immediately.
AvailableHarborGuard scores this vulnerability at CVSS 9.3 Critical and is capable of weighting that score against each customer organization's compliance policy to determine escalation priority. Triage results are routed to the appropriate team inbox within each customer environment based on configured ownership rules.
AvailableBecause no upstream fix version has been published, HarborGuard re-evaluates this advisory on every ingest cycle and will make a patched-image rebuild available the moment a remediated version is released. For customers who have opted into auto-remediation, the rebuild, regression run, and PR against affected workloads will trigger automatically once an upstream fix exists.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The vulnerable plugin endpoint is exposed over the network, so an attacker must be able to send HTTP requests to the WordPress site to reach it.
- AuthenticationNot required
No account or session token of any kind is needed; the injection point is accessible to unauthenticated requests.
- Victim interactionNot required
The attacker sends crafted requests directly to the server; no user action or social-engineering step is required.
- Attack complexityDetail
Exploit conditions are straightforward and reliable, with no race conditions, special configurations, or environmental factors required to trigger the injection.
Blast Radius
- An attacker reads arbitrary rows from the WordPress database, including stored user credentials, session tokens, private post content, and plugin configuration data.
- Database contents from other applications sharing the same database server may be accessible depending on the MySQL user's granted privileges, because the CVSS scope is marked Changed.
- The affected service experiences limited availability impact, meaning targeted queries or repeated exploitation may degrade database responsiveness for legitimate users.
How HarborGuard Handles This
Available on HarborGuard: this CVE is matched against all customer images carrying the 워드프레스 결제 심플페이 plugin at version 5.5.6 or below, scored at CVSS 9.3 Critical, and surfaced for immediate triage. Because no upstream fix exists today, HarborGuard monitors the Patchstack advisory and the codemstory plugin repository on every ingest cycle. Where compliance policy permits, compensating controls can be documented in HarborGuard's policy layer, including network-policy rules that restrict public access to affected WordPress endpoints, web-application firewall rule suggestions, and feature-flag or plugin-deactivation guidance. The moment an upstream patch is published, a patched-image rebuild becomes available, and for customers with auto-remediation enabled, HarborGuard opens a PR against affected workloads with a regression test run attached, with a typical median time from CVE patch publication to merged PR of around 90 minutes for Critical-severity issues in auto-remediation environments.
- codemstory / 워드프레스 결제 심플페이≤ 5.5.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L